CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

926 vulnerabilities with CWE-266
CVE-2025-0783 MEDIUM
Pankajindevops <20241113 - Info Disclosure
CVSS 6.3
CVE-2025-23528 HIGH
Wouter Dijkstra DD Roles <4.1 - Privilege Escalation
CVSS 8.8
CVE-2025-0484 HIGH
Fanli2012 native-php-cms 1.0 - Auth Bypass
CVSS 7.3
CVE-2025-22736 HIGH
WPExperts User Management <1.2 - Privilege Escalation
CVSS 8.8
CVE-2025-0206 MEDIUM
code-projects Online Shoe Store 1.0 - Info Disclosure
CVSS 5.3
CVE-2024-32009 HIGH
Spectrum Power 4 <V4.70 SP12 Update 2 - Privilege Escalation
CVSS 7.8
CVE-2024-58273 HIGH
Nagios Log Server < 2024R1.0.2 - Local Privilege Escalation from Apache User to Root
CVSS 7.8
CVE-2024-49731 MEDIUM
Android - Local Privilege Escalation via Telemetry Opt-In Settings Corruption
CVSS 4.0
CVE-2024-32444 CRITICAL
InspiryThemes RealHomes <4.3.6 - Privilege Escalation
CVSS 9.8
CVE-2024-12303 MEDIUM
GitLab 17.7-18.0.5, 18.1-18.1.3, 18.2-18.2.1 - Authenticated Incorrect Privilege Assignment via User Invitation
CVSS 6.7
CVE-2024-51800 CRITICAL
Favethemes Homey <2.4.1 - Privilege Escalation
CVSS 9.8
CVE-2024-49561 HIGH
Dell SmartFabric OS10 Software - Privilege Escalation
CVSS 7.8
CVE-2024-55570 MEDIUM
Cubro EXA48200 <20231025055018 - Privilege Escalation
CVSS 5.4
CVE-2024-8420 CRITICAL
DHVC Form <2.4.7 - Privilege Escalation
CVSS 9.8
CVE-2024-56000 CRITICAL
SeventhQueen K Elements <5.4.0 - Privilege Escalation
CVSS 9.8
CVE-2024-12213 CRITICAL
Apusthemes Superio < 1.2.76 - Incorrect Privilege Assignment
CVSS 9.8
CVE-2024-13421 CRITICAL
The Real Estate 7 WordPress theme - Privilege Escalation
CVSS 9.8
CVE-2024-40591 HIGH
Fortinet FortiOS <7.6.0, 7.4.0-7.4.4, 7.2.0-7.2.9 - Privilege Escal...
CVSS 8.8
CVE-2024-49348 MEDIUM
IBM Cloud Pak for Business Automation 18.0.0-22.0.2 - Incorrect Privilege Assignment via Task Reassignment
CVSS 4.3
CVE-2024-57967 MEDIUM
CyberArk Privileged Access Manager Self-Hosted <14.4 - Privilege Es...
CVSS 4.2
CVE-2024-43333 HIGH
NotFound Admin and Site Enhancements (ASE) Pro <7.6.2.1 - Privilege...
CVSS 7.5
CVE-2024-46974 HIGH
Software <version> - Info Disclosure
CVSS 7.8
CVE-2024-35122 LOW
IBM i 7.2-7.5 - Unauthenticated Local Denial of Service via Referential Constraint Configuration
CVSS 2.8
CVE-2024-51888 CRITICAL
Homey Login Register <2.4.0 - Privilege Escalation
CVSS 9.8
CVE-2024-32555 CRITICAL
NotFound Easy Real Estate <2.2.6 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 926