VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,180)

page 6 of 59
  • CVE-2023-1174CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.

  • CVE-2019-10940CriJan 16, 2020
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1). Incorrect session validation could allow an attacker with a valid session, with low privileges, to perform firmware updates and other administrative operations on connected devices. The…

  • CVE-2026-12294CriJun 16, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2025-10644CriSep 17, 2025
    risk 0.61cvss 9.4epss 0.03

    Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2026-64639CriAug 12, 2026
    risk 0.60cvss —epss 0.00

    Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.

  • CVE-2025-41115CriNov 21, 2025
    risk 0.60cvss 10.0epss 0.19

    SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is enabled and configured, a…

  • CVE-2022-20759HigMay 3, 2022
    risk 0.60cvss 8.8epss 0.28

    A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15.…

  • CVE-2026-86153CriSep 6, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

  • CVE-2026-10059CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the…

  • CVE-2025-10263CriJun 9, 2026
    risk 0.59cvss 9.1epss 0.01

    Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher…

  • CVE-2026-32519CriMar 25, 2026
    risk 0.59cvss 9.0epss 0.00

    Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.

  • CVE-2026-22908CriJan 15, 2026
    risk 0.59cvss 9.1epss 0.01

    Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

  • CVE-2025-45006CriJul 1, 2025
    risk 0.59cvss 9.1epss 0.00

    Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks.

  • CVE-2024-25660CriOct 1, 2024
    risk 0.59cvss 9.0epss 0.01

    The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.

  • CVE-2024-8253HigSep 11, 2024
    risk 0.58cvss 8.8epss 0.09

    The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is active. This makes it possible for…

  • CVE-2026-94036HigSep 20, 2026
    risk 0.57cvss 8.8epss —

    A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack…

  • CVE-2026-90493HigSep 13, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a…

  • CVE-2026-62106HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.

  • CVE-2026-62102HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.

  • CVE-2026-86482HigSep 7, 2026
    risk 0.57cvss 8.8epss 0.00

    In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation