CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

1,014 vulnerabilities with CWE-266
CVE-2025-7947 MEDIUM
jshERP < 3.5 - Improper Authorization via Account Handler ID Parameter
CVSS 5.4
CVE-2025-44655 CRITICAL
TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9 - Privilege Escalation via vsftpd chroot_local_user Misconfiguration
CVSS 9.8
CVE-2025-52836 CRITICAL
Unity Business Technology Pty Ltd The E-Commerce ERP <2.1.1.3 - Pri...
CVSS 9.8
CVE-2025-34112 CRITICAL
Riverbed SteelCentral NetProfiler & NetExpress <10.8.7 - RCE
CVE-2025-7576 HIGH
Teledyne FLIR FB- and FH-Series 1.3.2.16 - Improper Access Controls
CVSS 7.3
CVE-2025-7552 MEDIUM
Dromara Northstar <7.3.5 - Improper Access Controls
CVSS 6.3
CVE-2025-0140 MEDIUM
Palo Alto Networks GlobalProtect App - Privilege Escalation
CVE-2025-0139 MEDIUM
Palo Alto Networks Autonomous Digital Experience Manager - Privileg...
CVE-2025-27028 MEDIUM
Radiflow iSAP Smart Collector <1.20 - Info Disclosure
CVSS 6.8
CVE-2025-47422 HIGH
Advanced Installer <22.6 - Privilege Escalation
CVSS 7.5
CVE-2025-43001 MEDIUM
SAPCAR >= 7.53 < 7.53, >= 7.22EXT < 7.22EXT - Privilege Escalation via Archive Extraction
CVSS 6.9
CVE-2025-42992 MEDIUM
SAPCAR 7.22EXT-7.53 - Privilege Escalation via Malicious SAR Archive
CVSS 6.9
CVE-2025-7076 MEDIUM
BlackVue Dashcam 590X < 2025-06-24 - Unauthenticated Improper Access Control in Configuration Handler
CVSS 5.4
CVE-2025-49867 CRITICAL
RealHomes <= 4.4.0 - Privilege Escalation via Incorrect Privilege Assignment
CVSS 9.8
CVE-2025-23970 CRITICAL
aonetheme Service Finder Booking <6.0 - Privilege Escalation
CVSS 9.8
CVE-2025-27021 HIGH
Infinera G42 R6.1.3 - Privilege Escalation
CVSS 7.0
CVE-2025-45006 CRITICAL
Open-Source RISC-V Processor <f517abb - Memory Corruption
CVSS 9.1
CVE-2025-6765 MEDIUM
Intelbras InControl 2.21.60.9 - Incorrect Privilege Assignment via /v1/operador/ HTTP PUT Request
CVSS 6.3
CVE-2025-52726 HIGH
Pebas CouponXxL Custom Post Types <3.0 - Privilege Escalation
CVSS 8.6
CVE-2025-6736 MEDIUM
juzaweb CMS 3.4.2 - Incorrect Privilege Assignment in Add New Themes Page
CVSS 6.3
CVE-2025-6735 MEDIUM
juzaweb CMS 3.4.2 - Improper Authorization in Import Page
CVSS 6.3
CVE-2025-6702 MEDIUM
linlinjava litemall 1.8.0 - Incorrect Privilege Assignment via wx/comment/post adminComment Parameter
CVSS 4.3
CVE-2025-41255 HIGH
Cyberduck <9.1.6 - Mountain Duck <4.17.5 - Info Disclosure
CVSS 8.0
CVE-2025-23260 MEDIUM
NVIDIA AIStore < 2.3.0 - Incorrect Privilege Assignment via AIS Operator ServiceAccount
CVSS 5.0
CVE-2025-6532 MEDIUM
NOYAFA/Xiami LF9 Pro <20250611 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 1,014