CWE-266
Incorrect Privilege Assignment
Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
CVEs mapped to this weakness (1,180)
page 58 of 59| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-22078 | Hig | 0.00 | 7.3 | 0.00 | Jun 29, 2026 | Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel. | ||
| CVE-2026-13544 | Med | 0.00 | 6.3 | 0.00 | Jun 29, 2026 | A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be… | ||
| CVE-2026-13524 | Med | 0.00 | 5.6 | 0.00 | Jun 29, 2026 | A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper… | ||
| CVE-2026-13511 | Low | 0.00 | 3.1 | 0.00 | Jun 28, 2026 | A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a manipulation of the argument conversationId… | ||
| CVE-2026-49413 | Hig | 0.00 | 7.1 | 0.00 | Jun 27, 2026 | The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at the point where the auxiliary vector is constructed, so AT_SECURE was incorrectly set to zero for set-user-ID and… | ||
| CVE-2026-45259 | Med | 0.00 | 6.5 | 0.00 | Jun 27, 2026 | sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not include a capability mode check restricting signal delivery to the calling process's own PID. A process in capability mode can use… | ||
| CVE-2026-56033 | Cri | 0.00 | 9.8 | 0.00 | Jun 26, 2026 | Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. | ||
| CVE-2026-56030 | Cri | 0.00 | 9.8 | 0.00 | Jun 26, 2026 | Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. | ||
| CVE-2026-56028 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions. | ||
| CVE-2026-56010 | Hig | 0.00 | 8.8 | 0.00 | Jun 26, 2026 | Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | ||
| CVE-2026-56008 | Hig | 0.00 | 8.8 | 0.00 | Jun 26, 2026 | Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions. | ||
| CVE-2026-22315 | 0.00 | — | 0.00 | May 20, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||
| CVE-2026-22069 | — | 0.00 | — | 0.00 | May 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||
| CVE-2026-2209 | Med | 0.00 | 6.3 | 0.00 | Feb 8, 2026 | A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can… | ||
| CVE-2026-2206 | Med | 0.00 | 6.3 | 0.00 | Feb 8, 2026 | A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation results in improper access controls. It is possible to… | ||
| CVE-2026-1964 | Med | 0.00 | 4.3 | 0.00 | Feb 5, 2026 | A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix… | ||
| CVE-2026-1963 | Med | 0.00 | 6.3 | 0.00 | Feb 5, 2026 | A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgrading to version 8.21 mitigates… | ||
| CVE-2026-1962 | Med | 0.00 | 6.3 | 0.00 | Feb 5, 2026 | A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be initiated remotely. Upgrading to… | ||
| CVE-2026-1898 | Med | 0.00 | 6.3 | 0.00 | Feb 5, 2026 | A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component LDAP User Sync. This manipulation causes improper access controls. It is possible to initiate the attack remotely. Upgrading to… | ||
| CVE-2026-1896 | Med | 0.00 | 6.3 | 0.00 | Feb 5, 2026 | A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration Operation Handler. The manipulation of the argument boardId… |
- risk 0.00cvss 7.3epss 0.00
Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.
- risk 0.00cvss 6.3epss 0.00
A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be…
- risk 0.00cvss 5.6epss 0.00
A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper…
- risk 0.00cvss 3.1epss 0.00
A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a manipulation of the argument conversationId…
- risk 0.00cvss 7.1epss 0.00
The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at the point where the auxiliary vector is constructed, so AT_SECURE was incorrectly set to zero for set-user-ID and…
- risk 0.00cvss 6.5epss 0.00
sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not include a capability mode check restricting signal delivery to the calling process's own PID. A process in capability mode can use…
- risk 0.00cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
- risk 0.00cvss 9.8epss 0.01
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions.
- risk 0.00cvss 8.8epss 0.00
Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
- risk 0.00cvss 8.8epss 0.00
Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.
- CVE-2026-22315May 20, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- CVE-2026-22069May 19, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.00cvss 6.3epss 0.00
A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can…
- risk 0.00cvss 6.3epss 0.00
A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation results in improper access controls. It is possible to…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgrading to version 8.21 mitigates…
- risk 0.00cvss 6.3epss 0.00
A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be initiated remotely. Upgrading to…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component LDAP User Sync. This manipulation causes improper access controls. It is possible to initiate the attack remotely. Upgrading to…
- risk 0.00cvss 6.3epss 0.00
A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration Operation Handler. The manipulation of the argument boardId…