CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

739 vulnerabilities with CWE-266
CVE-2026-3817 MEDIUM
Patients Waiting Area Queue 1.0 - Auth Bypass
CVSS 5.3
CVE-2026-3796 MEDIUM
Qi-ANXIN QAX Virus Removal - Privilege Escalation
CVSS 5.3
CVE-2026-3764 HIGH
SourceCodester Client DBMS 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-3762 HIGH
SourceCodester CDMS 1.0/3.1 - Auth Bypass
CVSS 7.3
CVE-2026-3761 MEDIUM
SourceCodester Client DBMS 1.0 - Auth Bypass
CVSS 5.4
CVE-2026-3738 MEDIUM
SourceCodester Pet Grooming 1.0 - Auth Bypass
CVSS 6.3
CVE-2026-3737 MEDIUM
SourceCodester Pet Grooming 1.0 - Auth Bypass
CVSS 6.3
CVE-2026-3734 HIGH
SourceCodester Client DBMS 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-3724 MEDIUM
Patients Waiting Area Queue 1.0 - Auth Bypass
CVSS 6.3
CVE-2026-3675 MEDIUM
Freedom Factory dGEN1 <20260221 - Auth Bypass
CVSS 5.3
CVE-2026-3674 MEDIUM
Freedom Factory dGEN1 <20260221 - Auth Bypass
CVSS 5.3
CVE-2026-3671 LOW
Freedom Factory dGEN1 <20260221 - Auth Bypass
CVSS 3.3
CVE-2026-3670 MEDIUM
Freedom Factory dGEN1 <=20260221 - Privilege Escalation
CVSS 5.3
CVE-2026-3669 MEDIUM
Freedom Factory dGEN1 <20260221 - Privilege Escalation
CVSS 5.3
CVE-2026-3668 LOW
Freedom Factory dGEN1 <=20260221 - Auth Bypass
CVSS 3.1
CVE-2026-3667 MEDIUM
Freedom Factory dGEN1 <20260221 - Privilege Escalation
CVSS 5.3
CVE-2026-27983 CRITICAL
LMS Elementor Pro <=1.0.4 - Privilege Escalation
CVSS 9.8
CVE-2026-27541 HIGH
Wholesale Suite <=2.2.6 - Privilege Escalation
CVSS 7.1
CVE-2026-24963 HIGH
Amelia ameliabooking <=1.2.38 - Privilege Escalation
CVSS 7.2
CVE-2026-21425 MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2025-15597 MEDIUM
Dataease SQLBot <1.4.0 - Auth Bypass
CVSS 6.3
CVE-2026-0871 MEDIUM
Keycloak - Privilege Escalation
CVSS 4.9
CVE-2026-3268 MEDIUM
psi-probe PSI Probe <=5.3.0 - Auth Bypass
CVSS 5.4
CVE-2026-3265 MEDIUM
go2ismail Free-CRM - Auth Bypass
CVSS 6.3
CVE-2026-3263 MEDIUM
Asp.Net-Core-Inventory-Order-Management-System <9.20250118 - Auth B...
CVSS 6.3
Details
Vulnerabilities 739