VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,180)

page 7 of 59
  • CVE-2026-81769HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.

  • CVE-2026-82807HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit…

  • CVE-2026-82628HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper…

  • CVE-2026-32561HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

  • CVE-2026-28191HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.

  • CVE-2026-72840HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries…

  • CVE-2026-72839CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.01

    filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and…

  • CVE-2026-28161HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.

  • CVE-2026-28111HigAug 6, 2026
    risk 0.57cvss 8.8epss 0.00

    Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

  • CVE-2026-17626HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.

  • CVE-2026-54805HigJun 17, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

  • CVE-2025-69138HigJun 17, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.

  • CVE-2025-59563HigJun 17, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.

  • CVE-2026-12289HigJun 16, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-48889HigJun 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Amelia <= 2.3 versions.

  • CVE-2026-39579HigJun 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.

  • CVE-2026-49111HigJun 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.

  • CVE-2025-15656HigJun 3, 2026
    risk 0.57cvss 8.8epss 0.00

    Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.

  • CVE-2026-45216HigMay 25, 2026
    risk 0.57cvss 8.8epss 0.00

    Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.

  • CVE-2026-5141HigApr 29, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking a privileged process. This issue affects Pardus Software Center: from 1.0.2…