VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,068)

page 17 of 54
  • CVE-2025-26523HigFeb 14, 2025
    risk 0.48cvss epss 0.00

    This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information…

  • CVE-2024-13030HigDec 30, 2024
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/…

  • CVE-2024-12782HigDec 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads…

  • CVE-2024-27275HigJun 15, 2024
    risk 0.48cvss 7.4epss 0.00

    IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privileges of a user socially engineered to…

  • CVE-2023-3518HigAug 9, 2023
    risk 0.48cvss 7.4epss 0.00

    HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.

  • CVE-2022-4273HigDec 3, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. The manipulation of the argument…

  • CVE-2026-19376HigAug 10, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The…

  • CVE-2026-65559HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.00

    Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.

  • CVE-2026-12529HigJun 17, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access…

  • CVE-2026-49063HigJun 15, 2026
    risk 0.47cvss 7.3epss 0.00

    Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.

  • CVE-2026-39470HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.

  • CVE-2026-27407HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Editor Privilege Escalation in AI Engine <= 3.4.9 versions.

  • CVE-2026-53814HigJun 11, 2026
    risk 0.47cvss 8.3epss 0.00

    OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hooks/agent endpoint to cause…

  • CVE-2026-10236HigJun 1, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be…

  • CVE-2026-9562HigMay 26, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such manipulation leads to improper access controls. The attack may be launched remotely.…

  • CVE-2026-9517HigMay 26, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access…

  • CVE-2026-22315HigMay 20, 2026
    risk 0.47cvss 7.2epss 0.00

    Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export  of user data, including cleartext passwords, via the SQL editor. This issue affects Meona Client Launcher Component: through 19.06.2020…

  • CVE-2026-7644HigMay 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the…

  • CVE-2026-7468HigApr 30, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely.…

  • CVE-2026-6977HigApr 25, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been…