CWE-266
Incorrect Privilege Assignment
Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
CVEs mapped to this weakness (1,068)
page 50 of 54| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-17434 | Med | 0.00 | 6.3 | 0.00 | Jul 26, 2026 | A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The… | ||
| CVE-2026-17433 | Med | 0.00 | 5.3 | 0.00 | Jul 26, 2026 | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to… | ||
| CVE-2026-17432 | Med | 0.00 | 5.0 | 0.00 | Jul 26, 2026 | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId… | ||
| CVE-2026-16764 | Med | 0.00 | 6.3 | 0.00 | Jul 23, 2026 | A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be… | ||
| CVE-2026-61951 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | ||
| CVE-2026-59541 | Hig | 0.00 | 8.8 | 0.00 | Jul 23, 2026 | Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | ||
| CVE-2026-59540 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | ||
| CVE-2026-47237 | Hig | 0.00 | 8.0 | 0.00 | Jul 21, 2026 | Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from… | ||
| CVE-2026-21824 | Hig | 0.00 | 8.8 | 0.00 | Jul 20, 2026 | HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations. | ||
| CVE-2026-16224 | Med | 0.00 | 4.3 | 0.00 | Jul 19, 2026 | A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The… | ||
| CVE-2026-16199 | Med | 0.00 | 6.3 | 0.00 | Jul 19, 2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit… | ||
| CVE-2026-16121 | Med | 0.00 | 6.3 | 0.00 | Jul 18, 2026 | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly… | ||
| CVE-2026-50562 | Cri | 0.00 | — | 0.00 | Jul 15, 2026 | FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by… | ||
| CVE-2026-15594 | Low | 0.00 | 3.7 | 0.00 | Jul 13, 2026 | A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be… | ||
| CVE-2026-57813 | Cri | 0.00 | 9.8 | 0.00 | Jul 13, 2026 | Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3. | ||
| CVE-2026-57768 | Hig | 0.00 | 8.2 | 0.00 | Jul 13, 2026 | Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3. | ||
| CVE-2026-57410 | Hig | 0.00 | 8.8 | 0.00 | Jul 13, 2026 | Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2. | ||
| CVE-2026-57386 | Hig | 0.00 | 8.8 | 0.00 | Jul 13, 2026 | Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1. | ||
| CVE-2026-15510 | Med | 0.00 | 6.3 | 0.00 | Jul 12, 2026 | A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was… | ||
| CVE-2026-15509 | Med | 0.00 | 6.3 | 0.00 | Jul 12, 2026 | A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been… |
- risk 0.00cvss 6.3epss 0.00
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The…
- risk 0.00cvss 5.3epss 0.00
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to…
- risk 0.00cvss 5.0epss 0.00
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be…
- risk 0.00cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
- risk 0.00cvss 8.8epss 0.00
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
- risk 0.00cvss 8.0epss 0.00
Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from…
- risk 0.00cvss 8.8epss 0.00
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
- risk 0.00cvss 4.3epss 0.00
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The…
- risk 0.00cvss 6.3epss 0.00
A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly…
- risk 0.00cvss —epss 0.00
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by…
- risk 0.00cvss 3.7epss 0.00
A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be…
- risk 0.00cvss 9.8epss 0.00
Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.
- risk 0.00cvss 8.2epss 0.00
Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.
- risk 0.00cvss 8.8epss 0.00
Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.
- risk 0.00cvss 8.8epss 0.00
Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.
- risk 0.00cvss 6.3epss 0.00
A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was…
- risk 0.00cvss 6.3epss 0.00
A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been…