VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,068)

page 52 of 54
  • CVE-2026-14719HigJul 5, 2026
    risk 0.00cvss 7.3epss 0.00

    A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component Registration Endpoint. Executing a manipulation of the argument role can lead to improper privilege…

  • CVE-2026-14693MedJul 5, 2026
    risk 0.00cvss 5.4epss 0.00

    A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancel_order of the file classes/Master.php. Executing a manipulation can lead to improper authorization. The attack may be performed from…

  • CVE-2026-14690HigJul 5, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2026-59093HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The assignRoleToUser and assignRoleToGroup handlers (POST /authz/users/{id}/assign and /authz/groups/{id}/assign) authorize only that…

  • CVE-2026-57692CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.00

    Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.

  • CVE-2026-53902MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation. An attacker can add…

  • CVE-2026-56247HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pending invitees. Attackers can pre-seed malformed high-privilege bindings that survive invite acceptance, enabling accepted…

  • CVE-2026-13591MedJun 29, 2026
    risk 0.00cvss 5.0epss 0.00

    A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/managers/ChannelBridge.ts of the component Contact Tracking. This manipulation of the argument _channelType causes improper authorization. The attack may be…

  • CVE-2026-13568HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration Endpoint. This manipulation of the argument role causes improper access controls.…

  • CVE-2026-22078HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.

  • CVE-2026-13544MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be…

  • CVE-2026-13524MedJun 29, 2026
    risk 0.00cvss 5.6epss 0.00

    A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper…

  • CVE-2026-13511LowJun 28, 2026
    risk 0.00cvss 3.1epss 0.00

    A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a manipulation of the argument conversationId…

  • CVE-2026-49413HigJun 27, 2026
    risk 0.00cvss 7.1epss 0.00

    The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at the point where the auxiliary vector is constructed, so AT_SECURE was incorrectly set to zero for set-user-ID and…

  • CVE-2026-45259MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not include a capability mode check restricting signal delivery to the calling process's own PID. A process in capability mode can use…

  • CVE-2026-56033CriJun 26, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

  • CVE-2026-56030CriJun 26, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

  • CVE-2026-56028CriJun 26, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions.

  • CVE-2026-56010HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

  • CVE-2026-56008HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.