CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

914 vulnerabilities with CWE-266
CVE-2025-15084 LOW
youlai-mall 1.0.0/2.0.0 - Incorrect Privilege Assignment in Order Payment Handler
CVSS 3.1
CVE-2025-14889 MEDIUM
Campcodes Advanced Voting Management System 1.0 - Incorrect Privilege Assignment in Password Handler
CVSS 5.4
CVE-2025-64188 CRITICAL
PenciDesign Soledad <=8.6.9 - Privilege Escalation
CVSS 9.8
CVE-2025-59134 HIGH
Sale! Immigration law - Privilege Escalation
CVSS 8.8
CVE-2025-58710 HIGH
e-plugins Hotel Listing <1.4.0 - Privilege Escalation
CVSS 8.8
CVE-2025-55707 HIGH
WPXPO PostX <4.1.35 - Privilege Escalation
CVSS 7.2
CVE-2025-49379 HIGH
silverplugins217 Custom Fields Account Registration For Woocommerce...
CVSS 7.2
CVE-2025-14749 MEDIUM
Ningyuanda TC155 57.0.2.0 - Unauthenticated Incorrect Privilege Assignment in ONVIF PTZ Control Interface
CVSS 6.3
CVE-2025-14748 MEDIUM
Ningyuanda TC155 57.0.2.0 - Unauthenticated Hard Reset via ONVIF Device Management Service
CVSS 5.4
CVE-2025-14503 HIGH
Harmonix on AWS <0.4.2 - Privilege Escalation
CVSS 7.2
CVE-2025-13888 CRITICAL
Red Hat OpenShift GitOps < 1.16.2 - Authenticated Privilege Escalation via ArgoCD Custom Resource Injection
CVSS 9.1
CVE-2025-14660 MEDIUM
DecoCMS Mesh <1.0.0-alpha.31 - Improper Access Control
CVSS 5.6
CVE-2025-65807 HIGH
sd command <1.0.0 - Privilege Escalation
CVSS 8.4
CVE-2025-14206 MEDIUM
SourceCodester Online Student Clearance System 1.0 - Auth Bypass
CVSS 6.5
CVE-2025-14089 MEDIUM
Himool ERP <2.2 - Privilege Escalation
CVSS 6.3
CVE-2025-14088 MEDIUM
ketr JEPaaS <= 7.2.8 - Improper Authorization via /je/load Authorization Parameter
CVSS 6.3
CVE-2025-14086 MEDIUM
youlai-mall 1.0.0/2.0.0 - Improper Access Control via OpenID Parameter
CVSS 6.3
CVE-2025-14052 MEDIUM
youlai-mall 1.0.0/2.0.0 - Improper Access Control in getMemberById Function
CVSS 6.3
CVE-2025-55948 HIGH
yzcheng90 X-SpringBoot 6.0 - Incorrect Privilege Assignment via Frontend-Backend RBAC Desynchronization
CVSS 7.3
CVE-2025-14016 MEDIUM
macrozheng mall-swarm < 1.0.3 - Improper Authorization via /member/readHistory/delete ids Parameter
CVSS 5.4
CVE-2025-65842 MEDIUM
Aquarius HelperTool 1.0.003 - Privilege Escalation
CVSS 5.1
CVE-2025-66296 HIGH
Grav <1.8.0-beta.27 - Privilege Escalation
CVSS 8.8
CVE-2025-13808 HIGH
orionsec orion-ops - Incorrect Privilege Assignment in User Profile Handler
CVSS 7.3
CVE-2025-13807 MEDIUM
orionsec orion-ops < 2025-08-01 - Incorrect Privilege Assignment in MachineKeyController
CVSS 4.3
CVE-2025-13806 HIGH
nutzam NutzBoot < 2.6.0 - Improper Authorization in Transaction API
CVSS 7.3
Details
Vulnerabilities 914