A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
914 vulnerabilities with CWE-266
CVE-2026-10218
MEDIUM
nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization
CVSS 5.4
CVE-2026-10217
MEDIUM
nextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges management
CVSS 6.3
CVE-2026-10215
MEDIUM
Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorization
CVSS 4.3
CVE-2026-10152
MEDIUM
TaleLin lin-cms-spring-boot book Endpoint BookController.java access control
CVSS 6.3
CVE-2026-10070
MEDIUM
macrozheng mall Super Admin Password update improper authorization
CVSS 4.7
CVE-2026-35671
HIGH
phpMyFAQ - Insecure Direct Object Reference in User Password API
CVSS 8.8
CVE-2026-9795
HIGH
Keycloak: keycloak: privilege escalation via improper scope mapping enforcement
CVSS 7.3
CVE-2026-42758
CRITICAL
WordPress WebinarIgnition plugin < 4.08.253 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-42731
CRITICAL
WordPress miniorange otp verification plugin <= 5.4.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-9604
MEDIUM
JeecgBoot AiragModelController access control
CVSS 4.3
CVE-2026-9581
MEDIUM
JeecgBoot add access control
CVSS 6.3
CVE-2026-9580
HIGH
JeecgBoot selectDepart LoginController.selectDepart access control
CVSS 7.3
CVE-2026-9579
MEDIUM
JeecgBoot SysUser userEdit user.getUsername access control
CVSS 6.3
CVE-2026-9562
HIGH
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
CVSS 7.3
CVE-2026-9517
HIGH
hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control
CVSS 7.3
CVE-2026-45216
HIGH
WordPress Smart Manager plugin <= 8.85.0 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-9484
MEDIUM
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
CVSS 6.3
CVE-2026-9483
MEDIUM
SourceCodester Student Grades Management System grades.php improper authorization
CVSS 6.3
CVE-2026-9412
MEDIUM
SourceCodester Indian Invoicing System Backend Endpoint access control
CVSS 6.3
CVE-2026-9410
MEDIUM
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
CVSS 4.3
CVE-2026-9409
MEDIUM
Sushmi-pal Invoice-System User Management user improper authorization
CVSS 4.3
CVE-2026-9397
HIGH
Besen BS20 EV Charging Station OTA Update Installation improper authorization
CVSS 8.1
CVE-2026-9376
MEDIUM
JPress UCenter Article Submission Endpoint doWriteSave improper authorization
CVSS 6.3
CVE-2026-48172
CRITICAL
KEV
LiteSpeed cPanel Plugin < 2.4.5 - Privilege Escalation via Redis Feature Mishandling
CVSS 9.8
CVE-2026-22315
HIGH
Mesalvo Meona Client Launcher <= 19.06.2020 & Server <= 2025.04 - Unprotected User Data Exposure
CVSS 7.2
Details
Vulnerabilities
914