CWE-266
Incorrect Privilege Assignment
Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Hierarchy (View 1000)
CVEs mapped to this weakness (1,180)
page 7 of 59| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-81769 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2026 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. | ||
| CVE-2026-82807 | Hig | 0.57 | 8.8 | 0.00 | Aug 31, 2026 | A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit… | ||
| CVE-2026-82628 | Hig | 0.57 | 8.8 | 0.00 | Aug 31, 2026 | A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper… | ||
| CVE-2026-32561 | Hig | 0.57 | 8.8 | 0.00 | Aug 24, 2026 | Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | ||
| CVE-2026-28191 | Hig | 0.57 | 8.8 | 0.00 | Aug 18, 2026 | Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. | ||
| CVE-2026-72840 | Hig | 0.57 | 8.8 | 0.00 | Aug 13, 2026 | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries… | ||
| CVE-2026-72839 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and… | ||
| CVE-2026-28161 | Hig | 0.57 | 8.8 | 0.00 | Aug 13, 2026 | Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | ||
| CVE-2026-28111 | Hig | 0.57 | 8.8 | 0.00 | Aug 6, 2026 | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | ||
| CVE-2026-17626 | Hig | 0.57 | 8.8 | 0.00 | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments. | ||
| CVE-2026-54805 | Hig | 0.57 | 8.8 | 0.00 | Jun 17, 2026 | Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. | ||
| CVE-2025-69138 | Hig | 0.57 | 8.8 | 0.00 | Jun 17, 2026 | Subscriber Privilege Escalation in Genemy <= 1.6.6 versions. | ||
| CVE-2025-59563 | Hig | 0.57 | 8.8 | 0.00 | Jun 17, 2026 | Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions. | ||
| CVE-2026-12289 | Hig | 0.57 | 8.8 | 0.00 | Jun 16, 2026 | Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | ||
| CVE-2026-48889 | Hig | 0.57 | 8.8 | 0.00 | Jun 15, 2026 | Subscriber Privilege Escalation in Amelia <= 2.3 versions. | ||
| CVE-2026-39579 | Hig | 0.57 | 8.8 | 0.00 | Jun 15, 2026 | Contributor Privilege Escalation in B Blocks <= 2.0.31 versions. | ||
| CVE-2026-49111 | Hig | 0.57 | 8.8 | 0.00 | Jun 15, 2026 | Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0. | ||
| CVE-2025-15656 | Hig | 0.57 | 8.8 | 0.00 | Jun 3, 2026 | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. | ||
| CVE-2026-45216 | Hig | 0.57 | 8.8 | 0.00 | May 25, 2026 | Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0. | ||
| CVE-2026-5141 | Hig | 0.57 | 8.8 | 0.00 | Apr 29, 2026 | Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking a privileged process. This issue affects Pardus Software Center: from 1.0.2… |
- risk 0.57cvss 8.8epss 0.00
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
- risk 0.57cvss 8.8epss 0.00
A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit…
- risk 0.57cvss 8.8epss 0.00
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper…
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
- risk 0.57cvss 8.8epss 0.00
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries…
- risk 0.57cvss 9.8epss 0.01
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and…
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
- risk 0.57cvss 8.8epss 0.00
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
- risk 0.57cvss 8.8epss 0.00
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.
- risk 0.57cvss 8.8epss 0.00
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
- risk 0.57cvss 8.8epss 0.00
Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.
- risk 0.57cvss 8.8epss 0.00
Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.
- risk 0.57cvss 8.8epss 0.00
Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.
- risk 0.57cvss 8.8epss 0.00
Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.
- risk 0.57cvss 8.8epss 0.00
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking a privileged process. This issue affects Pardus Software Center: from 1.0.2…