CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

1,014 vulnerabilities with CWE-266
CVE-2026-53902 MEDIUM
Mycomplianceoffice Mco < 25.3.3.1 - Privilege Escalation
CVSS 6.5
CVE-2026-56247 HIGH
Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment
CVSS 8.8
CVE-2026-4629 MEDIUM
Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
CVSS 6.5
CVE-2026-12388 MEDIUM
Keycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapper
CVSS 6.5
CVE-2026-13591 MEDIUM
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
CVSS 5.0
CVE-2026-13568 HIGH
SourceCodester Inventory Management System User Registration Endpoint users_handler.php access control
CVSS 7.3
CVE-2026-22078 HIGH
O+ Connect's lack of authentication for IPC channels led to a local privilege escalation vulnerability.
CVSS 7.3
CVE-2026-13544 MEDIUM
Feehi CMS API users access control
CVSS 6.3
CVE-2026-13524 MEDIUM
CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization
CVSS 5.6
CVE-2026-13511 LOW
VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization
CVSS 3.1
CVE-2026-49413 HIGH
FreeBSD - Flaw in Linuxulator Execution of Setugid Binaries
CVSS 7.1
CVE-2026-45259 MEDIUM
FreeBSD - Sigqueue(2) Missing Capability Mode Restriction
CVSS 6.5
CVE-2026-56033 CRITICAL
WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-56030 CRITICAL
WordPress Paytium plugin <= 5.0.2 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-56028 CRITICAL
WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= 1.4.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-56010 HIGH
WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-56008 HIGH
WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-12164 MEDIUM
Privilege Escalation in Fortra File Integrity Monitoring (FIM)
CVSS 4.4
CVE-2026-12823 LOW
Browserbase Autobrowse Trace Artifact default permission
CVSS 3.3
CVE-2026-56251 MEDIUM
Capgo - Privilege Escalation via Broken Row Level Security in org_users
CVSS 6.5
CVE-2026-12799 MEDIUM
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
CVSS 4.3
CVE-2026-12786 HIGH
Ezbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access control
CVSS 7.8
CVE-2026-12784 HIGH
IM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access control
CVSS 7.8
CVE-2026-12782 HIGH
EaseUS Partition Master Kernel Driver EUEDKEPM.sys access control
CVSS 7.8
CVE-2026-12781 HIGH
EaseUS Partition Master Kernel Driver epmntdrv.sys access control
CVSS 7.8
Details
Vulnerabilities 1,014