A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
1,014 vulnerabilities with CWE-266
CVE-2026-52791
LOW
fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC)
CVE-2026-17434
MEDIUM
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
CVSS 6.3
CVE-2026-17433
MEDIUM
nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
CVSS 5.3
CVE-2026-17432
MEDIUM
NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
CVSS 5.0
CVE-2026-16764
MEDIUM
OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
CVSS 6.3
CVE-2026-61951
CRITICAL
WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-59541
HIGH
WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-59540
CRITICAL
WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-47237
HIGH
Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Authorization Token Stealing
CVSS 8.0
CVE-2026-21824
HIGH
A privilege escalation vulnerability affects HCL Commerce
CVSS 8.8
CVE-2026-16224
MEDIUM
jxxghp MoviePilot Application API improper authorization
CVSS 4.3
CVE-2026-16199
MEDIUM
nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper authorization
CVSS 6.3
CVE-2026-16121
MEDIUM
nextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization
CVSS 6.3
CVE-2026-50562
CRITICAL
FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows
CVE-2026-15594
LOW
waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization
CVSS 3.7
CVE-2026-57813
CRITICAL
WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-57768
HIGH
WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulnerability
CVSS 8.2
CVE-2026-57410
HIGH
WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-57386
HIGH
WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-15510
MEDIUM
Leantime API saveSetting improper authorization
CVSS 6.3
CVE-2026-15509
MEDIUM
Leantime JSON-RPC Endpoint addUser improper authorization
CVSS 6.3
CVE-2026-15499
MEDIUM
AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization
CVSS 6.3
CVE-2026-15476
MEDIUM
QILING Disk Master Kernel Driver diskbckp.sys access control
CVSS 5.3
CVE-2026-15475
MEDIUM
MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control
CVSS 5.3
CVE-2026-15474
MEDIUM
Eleveo Call Recording Software audio.jsp improper authorization
CVSS 4.3
Details
Vulnerabilities
1,014