VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,068)

page 50 of 54
  • CVE-2026-17434MedJul 26, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The…

  • CVE-2026-17433MedJul 26, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to…

  • CVE-2026-17432MedJul 26, 2026
    risk 0.00cvss 5.0epss 0.00

    A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId…

  • CVE-2026-16764MedJul 23, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be…

  • CVE-2026-61951CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

  • CVE-2026-59541HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.00

    Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

  • CVE-2026-59540CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

  • CVE-2026-47237HigJul 21, 2026
    risk 0.00cvss 8.0epss 0.00

    Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from…

  • CVE-2026-21824HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2026-16224MedJul 19, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The…

  • CVE-2026-16199MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit…

  • CVE-2026-16121MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly…

  • CVE-2026-50562CriJul 15, 2026
    risk 0.00cvss epss 0.00

    FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by…

  • CVE-2026-15594LowJul 13, 2026
    risk 0.00cvss 3.7epss 0.00

    A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be…

  • CVE-2026-57813CriJul 13, 2026
    risk 0.00cvss 9.8epss 0.00

    Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.

  • CVE-2026-57768HigJul 13, 2026
    risk 0.00cvss 8.2epss 0.00

    Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.

  • CVE-2026-57410HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.

  • CVE-2026-57386HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

  • CVE-2026-15510MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was…

  • CVE-2026-15509MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been…