CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

926 vulnerabilities with CWE-266
CVE-2024-7480 MEDIUM
Avaya Aura System Manager 10.1.x.x and 10.2.x.x - Authenticated Arbitrary File Read via CLI
CVSS 4.2
CVE-2024-41139 HIGH
SKYSEA Client View 6.010.06-19.210.04e - Privilege Escalation via DLL Placement
CVSS 7.8
CVE-2024-40433 HIGH
Tencent WeChat <8.0.37 - Privilege Escalation
CVSS 8.8
CVE-2024-36534 HIGH
hwameistor <0.14.3 - Privilege Escalation
CVSS 8.4
CVE-2024-23794 MEDIUM
OTRS 8.0.X, 2023.X, 2024.X-2024.4.x - Privilege Escalation via Inline Editing Functionality
CVSS 5.2
CVE-2024-37927 CRITICAL
NooTheme Jobmonster <4.7.0 - Privilege Escalation
CVSS 9.8
CVE-2024-31315 HIGH
Android - Local Privilege Escalation via Notification Access Settings
CVSS 7.8
CVE-2024-38278 MEDIUM
RUGGEDCOM Various - Info Disclosure
CVSS 6.6
CVE-2024-37134 MEDIUM
Dell PowerScale OneFS 8.2.2-9.8.0.0 - Privilege Escalation to Root
CVSS 6.7
CVE-2024-37132 MEDIUM
Dell PowerScale OneFS 8.2.2-9.8.0.0 - Denial of Service and Privilege Escalation
CVSS 6.7
CVE-2024-31912 HIGH
IBM MQ 9.3 LTS and 9.3 CD - Authenticated Privilege Escalation via Incorrect Privilege Assignment
CVSS 7.5
CVE-2024-27275 HIGH
IBM i 7.2-7.5 - Incorrect Privilege Assignment in Physical File Trigger Configuration
CVSS 7.4
CVE-2024-0085 MEDIUM
NVIDIA vGPU < 13.11 and Cloud Gaming < 555.52.04 - Privilege Escalation
CVSS 6.3
CVE-2024-36587 HIGH
DNSCrypt-proxy <2.1.5 - Privilege Escalation
CVSS 7.8
CVE-2024-37293 HIGH
AWS Deployment Framework < 4.0.0 - Privilege Escalation via Bootstrap CodeBuild Role
CVSS 7.5
CVE-2024-35700 CRITICAL
Userpro <= 5.1.8 - Unauthenticated Account Takeover via Incorrect Privilege Assignment
CVSS 9.8
CVE-2024-4870 HIGH
Frontend Registration - Contact Form 7 <5.1 - Privilege Escalation
CVSS 7.2
CVE-2024-32959 HIGH
Sirv <= 7.2.2 - Incorrect Privilege Assignment via Arbitrary Option Update
CVSS 8.8
CVE-2024-32507 HIGH
Hamid Alinia - idehweb <1.7.16 - Privilege Escalation
CVSS 8.8
CVE-2024-24882 CRITICAL
Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation
CVSS 9.8
CVE-2024-22145 HIGH
InstaWP Connect <0.1.0.8 - Privilege Escalation
CVSS 8.8
CVE-2024-20389 HIGH
Cisco ConfD/Crosswork - Privilege Escalation
CVSS 7.8
CVE-2024-31771 HIGH
TotalAV <6.0.740 - Privilege Escalation
CVSS 7.8
CVE-2024-27460 MEDIUM
Plantronics Hub <3.25.1 - Privilege Escalation
CVSS 6.7
CVE-2024-27273 HIGH
IBM AIX 7.2-7.3 and VIOS 3.1-4.1 - Privilege Escalation via Unix Domain Datagram Socket SO_PEERID Operation
CVSS 8.1
Details
Vulnerabilities 926