CWE-266
Incorrect Privilege Assignment
Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
CVEs mapped to this weakness (1,181)
page 2 of 60| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73347 | Cri | 0.64 | 9.8 | 0.00 | Aug 19, 2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | ||
| CVE-2026-66424 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | ||
| CVE-2026-66662 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||
| CVE-2026-65507 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | ||
| CVE-2026-54807 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. | ||
| CVE-2026-49058 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. | ||
| CVE-2026-27395 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. | ||
| CVE-2025-69179 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. | ||
| CVE-2026-39583 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions. | ||
| CVE-2026-34901 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. | ||
| CVE-2026-49060 | Cri | 0.64 | 9.8 | 0.02 | Jun 11, 2026 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4. | ||
| CVE-2025-53209 | Cri | 0.64 | 9.8 | 0.00 | Jun 2, 2026 | Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0. | ||
| CVE-2026-48879 | Cri | 0.64 | 9.8 | 0.00 | Jun 1, 2026 | Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17. | ||
| CVE-2026-42680 | Cri | 0.64 | 9.8 | 0.00 | Jun 1, 2026 | Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1. | ||
| CVE-2026-42758 | Cri | 0.64 | 9.8 | 0.01 | May 27, 2026 | Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253. | ||
| CVE-2026-42731 | Cri | 0.64 | 9.8 | 0.00 | May 27, 2026 | Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9. | ||
| CVE-2026-42368 | Cri | 0.64 | 9.9 | 0.01 | May 4, 2026 | A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability. | ||
| CVE-2026-22337 | Cri | 0.64 | 9.8 | 0.00 | Apr 27, 2026 | Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4. | ||
| CVE-2026-33519 | Cri | 0.64 | 9.8 | 0.00 | Apr 21, 2026 | An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials. | ||
| CVE-2026-33518 | Cri | 0.64 | 9.8 | 0.00 | Apr 21, 2026 | An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected. |
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
- risk 0.64cvss 9.8epss 0.02
Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.
- risk 0.64cvss 9.8epss 0.00
Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.
- risk 0.64cvss 9.8epss 0.00
Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.
- risk 0.64cvss 9.8epss 0.00
Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.
- risk 0.64cvss 9.8epss 0.01
Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.
- risk 0.64cvss 9.8epss 0.00
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.
- risk 0.64cvss 9.9epss 0.01
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.00
Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4.
- risk 0.64cvss 9.8epss 0.00
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
- risk 0.64cvss 9.8epss 0.00
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.