CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

1,014 vulnerabilities with CWE-266
CVE-2026-52791 LOW
fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC)
CVE-2026-17434 MEDIUM
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
CVSS 6.3
CVE-2026-17433 MEDIUM
nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
CVSS 5.3
CVE-2026-17432 MEDIUM
NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
CVSS 5.0
CVE-2026-16764 MEDIUM
OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
CVSS 6.3
CVE-2026-61951 CRITICAL
WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-59541 HIGH
WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-59540 CRITICAL
WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-47237 HIGH
Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Authorization Token Stealing
CVSS 8.0
CVE-2026-21824 HIGH
A privilege escalation vulnerability affects HCL Commerce
CVSS 8.8
CVE-2026-16224 MEDIUM
jxxghp MoviePilot Application API improper authorization
CVSS 4.3
CVE-2026-16199 MEDIUM
nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper authorization
CVSS 6.3
CVE-2026-16121 MEDIUM
nextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization
CVSS 6.3
CVE-2026-50562 CRITICAL
FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows
CVE-2026-15594 LOW
waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization
CVSS 3.7
CVE-2026-57813 CRITICAL
WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-57768 HIGH
WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulnerability
CVSS 8.2
CVE-2026-57410 HIGH
WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-57386 HIGH
WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-15510 MEDIUM
Leantime API saveSetting improper authorization
CVSS 6.3
CVE-2026-15509 MEDIUM
Leantime JSON-RPC Endpoint addUser improper authorization
CVSS 6.3
CVE-2026-15499 MEDIUM
AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization
CVSS 6.3
CVE-2026-15476 MEDIUM
QILING Disk Master Kernel Driver diskbckp.sys access control
CVSS 5.3
CVE-2026-15475 MEDIUM
MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control
CVSS 5.3
CVE-2026-15474 MEDIUM
Eleveo Call Recording Software audio.jsp improper authorization
CVSS 4.3
Details
Vulnerabilities 1,014