VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,180)

page 28 of 59
  • CVE-2026-77795MedAug 21, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to improper…

  • CVE-2026-76999MedAug 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be…

  • CVE-2026-75978MedAug 19, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads…

  • CVE-2026-68568MedAug 18, 2026
    risk 0.41cvss 6.3epss 0.00

    Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.

  • CVE-2026-19918MedAug 16, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network.…

  • CVE-2026-19358MedAug 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure.

  • CVE-2026-19007MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege management. It is possible to initiate the attack…

  • CVE-2026-19005MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/create-agent.ts of the component Child-Agent Creation. Performing a manipulation results in improper privilege management. Remote…

  • CVE-2026-18998MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the…

  • CVE-2026-18996MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command Handler. Such manipulation leads to incorrect…

  • CVE-2026-18993MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed…

  • CVE-2026-18976MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be…

  • CVE-2026-18723MedAug 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be…

  • CVE-2026-11532MedJun 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record Handler. Executing a manipulation can lead to improper access controls. The…

  • CVE-2026-11521MedJun 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controller/TransactionController.java of the…

  • CVE-2026-11519MedJun 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the component Account Creation Handler. The manipulation of the argument ROLE results in…

  • CVE-2026-11476MedJun 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this issue is the function edit-admin of the file controllers/AdminController.php of the component Profile Update Endpoint. The…

  • CVE-2026-11336MedJun 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown function of the file dashboard_page/admin_page.php of the component Admin Interface. The manipulation…

  • CVE-2026-10876MedJun 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper authorization. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2026-10693MedJun 3, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated…