CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

1,014 vulnerabilities with CWE-266
CVE-2026-15473 MEDIUM
Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization
CVSS 6.3
CVE-2026-15472 MEDIUM
Eleveo Call Recording Software composeEmailAction.do improper authorization
CVSS 4.3
CVE-2026-15471 MEDIUM
Eleveo Call Recording Software pci_dss_status.jsp improper authorization
CVSS 4.3
CVE-2026-15470 MEDIUM
Eleveo Call Recording Software group.jsp improper authorization
CVSS 4.3
CVE-2026-15377 MEDIUM
Eleveo Call Recording Software sendlogfile improper authorization
CVSS 4.3
CVE-2026-15376 MEDIUM
Eleveo Call Recording Software statisticReportAction.do improper authorization
CVSS 6.3
CVE-2026-15375 MEDIUM
Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization
CVSS 4.3
CVE-2026-15374 MEDIUM
Eleveo Call Recording Software Group roleAddAction.do improper authorization
CVSS 6.3
CVE-2026-15373 MEDIUM
Eleveo Call Recording Software userAddAction.do improper authorization
CVSS 6.3
CVE-2026-15319 HIGH
Sipeed PicoClaw Launcher access_control.go IPAllowlist access control
CVSS 7.3
CVE-2026-57501 NONE
Zen Browser < 1.21.5b - System Principal File URL Bypass
CVE-2026-15271 HIGH
TOTOLINK EX200 Web boa.conf least privilege violation
CVSS 7.5
CVE-2026-15270 HIGH
D-link DIR-823G Web boa.conf least privilege violation
CVSS 7.5
CVE-2026-15188 MEDIUM
manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmployeeProfileAPIView access control
CVSS 6.3
CVE-2026-33390 HIGH
Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
CVSS 8.1
CVE-2026-26053 MEDIUM
Gallagher Command Centre Server - Incorrect Privilege Assignment
CVSS 5.3
CVE-2026-14794 MEDIUM
Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization
CVSS 4.3
CVE-2026-14792 MEDIUM
Formbricks Survey actions.ts access control
CVSS 6.5
CVE-2026-14778 HIGH
SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
CVSS 7.3
CVE-2026-14719 HIGH
SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management
CVSS 7.3
CVE-2026-14693 MEDIUM
SourceCodester Multi-Vendor Online Grocery Management System Master.php cancel_order improper authorization
CVSS 5.4
CVE-2026-14690 HIGH
SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization
CVSS 7.3
CVE-2026-59093 HIGH
Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment
CVSS 8.8
CVE-2026-5136 HIGH
Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation
CVSS 8.8
CVE-2026-57692 CRITICAL
WordPress PrivateContent plugin <= 9.9.2 - Privilege Escalation vulnerability
CVSS 9.8
Details
Vulnerabilities 1,014