CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

917 vulnerabilities with CWE-266
CVE-2025-3744 HIGH
Nomad Enterprise < 1.8.13 - Policy Override Bypass in Job Submissions
CVSS 7.6
CVE-2025-40571 LOW
Mendix OIDC SSO <4.1.0, <4.0.1, <3.3.0 - Privilege Escalation
CVSS 2.2
CVE-2025-4374 MEDIUM
Red Hat Quay < 3.14.0 - Incorrect Privilege Assignment via Proxy Cache Repository Creation
CVSS 6.5
CVE-2025-2898 HIGH
IBM Maximo Application Suite 9.0 - Privilege Escalation via RBAC Misconfiguration
CVSS 7.5
CVE-2025-4269 MEDIUM
TOTOLINK A720R 4.1.5cu.374 - Improper Access Controls
CVSS 6.5
CVE-2025-3517 MEDIUM
Devolutions Server < 2025.1.6.0 - Privilege Escalation via PAM JIT Username Update
CVSS 6.3
CVE-2025-27007 CRITICAL
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
CVSS 9.8
CVE-2025-4136 MEDIUM
Weitong Mall 1.0.0 - Improper Authorization via Sale Endpoint ID Parameter
CVSS 5.4
CVE-2025-4119 MEDIUM
Weitong Mall 1.0.0 - Improper Access Control in Product Statistics Handler
CVSS 5.3
CVE-2025-4118 MEDIUM
Weitong Mall 1.0.0 - Improper Access Control in Product History Handler
CVSS 5.3
CVE-2025-4067 MEDIUM
ScriptAndTools Online-Travling-System 1.0 - Improper Access Control in /admin/viewpackage.php
CVSS 5.3
CVE-2025-4066 HIGH
ScriptAndTools Online-Travling-System 1.0 - Improper Access Control in /admin/addpackage.php
CVSS 7.3
CVE-2025-4065 HIGH
ScriptAndTools Online-Travling-System 1.0 - Improper Access Control in /admin/addadvertisement.php
CVSS 7.3
CVE-2025-4064 MEDIUM
ScriptAndTools Online-Travling-System 1.0 - Improper Access Control in /admin/viewenquiry.php
CVSS 5.3
CVE-2025-4036 MEDIUM
xxyopen novel 3.5.0 - Improper Access Control in AuthorController updateBookChapter
CVSS 6.3
CVE-2025-4017 MEDIUM
novel-plus < 5.1.1 - Improper Authorization in LogController
CVSS 4.3
CVE-2025-4016 MEDIUM
novel-plus < 5.1.1 - Improper Authorization in LogController deleteIndex Function
CVSS 5.4
CVE-2025-3981 MEDIUM
wowjoy Internet Doctor Workstation System 1.0 - Info Disclosure
CVSS 4.3
CVE-2025-3980 MEDIUM
wowjoy Internet Doctor Workstation System 1.0 - Auth Bypass
CVSS 4.3
CVE-2025-3977 MEDIUM
iteachyou Dreamer CMS <4.1.3 - Info Disclosure
CVSS 4.3
CVE-2025-3967 MEDIUM
itwanger paicoding 1.0.3 - Auth Bypass
CVSS 5.4
CVE-2025-2850 LOW
GL.iNet Various - Path Traversal
CVSS 3.5
CVE-2025-32980 CRITICAL
NETSCOUT nGeniusONE <6.4.0 P11 b3245 - Info Disclosure
CVSS 9.8
CVE-2025-2470 CRITICAL
Service Finder Bookings - Privilege Escalation
CVSS 9.8
CVE-2025-3790 MEDIUM
Apache Druid Monitoring Console - Improper Access Controls
CVSS 5.3
Details
Vulnerabilities 917