CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

917 vulnerabilities with CWE-266
CVE-2025-8261 HIGH
Vaelsys VaelsysV4 4.1.0 - Unauthenticated User Creation via vgrid_server.php
CVSS 7.3
CVE-2025-8181 HIGH
TOTOLINK N600R/X2000R 1.0.0.1 - Privilege Escalation
CVSS 7.2
CVE-2025-31513 MEDIUM
AlertEnterprise Guardian <4.1.14.2.2.1 - Privilege Escalation
CVSS 6.5
CVE-2025-7947 MEDIUM
jshERP < 3.5 - Improper Authorization via Account Handler ID Parameter
CVSS 5.4
CVE-2025-44655 CRITICAL
TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9 - Privilege Escalation via vsftpd chroot_local_user Misconfiguration
CVSS 9.8
CVE-2025-52836 CRITICAL
Unity Business Technology Pty Ltd The E-Commerce ERP <2.1.1.3 - Pri...
CVSS 9.8
CVE-2025-34112 CRITICAL
Riverbed SteelCentral NetProfiler & NetExpress <10.8.7 - RCE
CVE-2025-7576 HIGH
Teledyne FLIR FB- and FH-Series 1.3.2.16 - Improper Access Controls
CVSS 7.3
CVE-2025-7552 MEDIUM
Dromara Northstar <7.3.5 - Improper Access Controls
CVSS 6.3
CVE-2025-0140 MEDIUM
Palo Alto Networks GlobalProtect App - Privilege Escalation
CVE-2025-0139 MEDIUM
Palo Alto Networks Autonomous Digital Experience Manager - Privileg...
CVE-2025-27028 MEDIUM
Radiflow iSAP Smart Collector <1.20 - Info Disclosure
CVSS 6.8
CVE-2025-47422 HIGH
Advanced Installer <22.6 - Privilege Escalation
CVSS 7.5
CVE-2025-43001 MEDIUM
SAPCAR >= 7.53 < 7.53, >= 7.22EXT < 7.22EXT - Privilege Escalation via Archive Extraction
CVSS 6.9
CVE-2025-42992 MEDIUM
SAPCAR 7.22EXT-7.53 - Privilege Escalation via Malicious SAR Archive
CVSS 6.9
CVE-2025-7076 MEDIUM
BlackVue Dashcam 590X < 2025-06-24 - Unauthenticated Improper Access Control in Configuration Handler
CVSS 5.4
CVE-2025-49867 CRITICAL
RealHomes <= 4.4.0 - Privilege Escalation via Incorrect Privilege Assignment
CVSS 9.8
CVE-2025-23970 CRITICAL
aonetheme Service Finder Booking <6.0 - Privilege Escalation
CVSS 9.8
CVE-2025-27021 HIGH
Infinera G42 R6.1.3 - Privilege Escalation
CVSS 7.0
CVE-2025-45006 CRITICAL
Open-Source RISC-V Processor <f517abb - Memory Corruption
CVSS 9.1
CVE-2025-6765 MEDIUM
Intelbras InControl 2.21.60.9 - Incorrect Privilege Assignment via /v1/operador/ HTTP PUT Request
CVSS 6.3
CVE-2025-52726 HIGH
Pebas CouponXxL Custom Post Types <3.0 - Privilege Escalation
CVSS 8.6
CVE-2025-6736 MEDIUM
juzaweb CMS 3.4.2 - Incorrect Privilege Assignment in Add New Themes Page
CVSS 6.3
CVE-2025-6735 MEDIUM
juzaweb CMS 3.4.2 - Improper Authorization in Import Page
CVSS 6.3
CVE-2025-6702 MEDIUM
linlinjava litemall 1.8.0 - Incorrect Privilege Assignment via wx/comment/post adminComment Parameter
CVSS 4.3
Details
Vulnerabilities 917