CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

926 vulnerabilities with CWE-266
CVE-2024-27453 HIGH
Extreme XOS <22.6.1.4 - Privilege Escalation
CVSS 8.6
CVE-2024-31760 MEDIUM
flipped-aurora gin-vue-admin <2.4 - Privilege Escalation
CVSS 4.7
CVE-2024-2409 CRITICAL
MasterStudy LMS <3.3.1 - Privilege Escalation
CVSS 9.8
CVE-2024-3013 MEDIUM
FLIR AX8 Firmware < 1.46.16 - Improper Authorization via User Registration
CVSS 6.3
CVE-2024-20320 HIGH
Cisco IOS XR - Privilege Escalation
CVSS 7.8
CVE-2024-23288 HIGH
iPadOS < 17.4 - Privilege Escalation
CVSS 7.8
CVE-2024-25083 MEDIUM
BeyondTrust Privilege Management <24.1 - Privilege Escalation
CVSS 6.3
CVE-2024-23976 MEDIUM
F5 BIG-IP and BIG-IQ - Authenticated Privilege Escalation via iAppsLX Template Bypass
CVSS 6.0
CVE-2023-26280 MEDIUM
IBM Jazz Foundation <7.0.3 - Info Disclosure
CVSS 5.3
CVE-2023-7270 MEDIUM
SoftMaker Office/FreOffice <1214 - Local Privilege Escalation
CVSS 5.3
CVE-2023-38298 HIGH
TCL 30Z A3X 20XE 10L - Unauthenticated IMEI Leak via System Property
CVSS 8.8
CVE-2023-38296 HIGH
TCL 30Z and A3X - Unauthenticated ICCID Exposure via System Property
CVSS 8.0
CVE-2023-50437 HIGH
Couchbase Server < 7.2.4 - Incorrect Privilege Assignment via otpCookie Exposure
CVSS 8.6
CVE-2023-6477 MEDIUM
GitLab EE <16.7.6-16.8.3-16.9.1 - Privilege Escalation
CVSS 6.7
CVE-2023-40109 HIGH
Android - Local Privilege Escalation via UsbConfiguration Parcel Handling
CVSS 7.8
CVE-2023-6815 MEDIUM
Mitsubishielectric R08sfcpu Firmware - Incorrect Privilege Assignment
CVSS 6.5
CVE-2023-5080 MEDIUM
Lenovo Tablet - Privilege Escalation
CVSS 6.8
CVE-2023-49647 HIGH
Zoom Desktop Client, VDI Client, and SDKs for Windows < 5.16.10 - Authenticated Privilege Escalation via Local Access
CVSS 8.8
CVE-2023-47140 MEDIUM
IBM CICS Transaction Gateway 9.3 - Unauthorized File Access via Improper Access Controls
CVSS 4.0
CVE-2023-29066 LOW
FACSChorus - Improper Privilege Management in Local Application Data Folders
CVSS 3.2
CVE-2023-6009 HIGH
UserPro WordPress <5.1.4 - Privilege Escalation
CVSS 8.8
CVE-2023-5913 HIGH
Fortify ScanCentral DAST 21.1-23.1 - Incorrect Privilege Assignment
CVSS 8.2
CVE-2023-5077 HIGH
HashiCorp Vault < 1.13.0 - Incorrect Privilege Assignment in Google Cloud Secrets Engine
CVSS 7.6
CVE-2023-3775 MEDIUM
Vault 0.11.0-1.13.7 - Denial of Service via Sentinel Role Governing Policy
CVSS 4.2
CVE-2023-4153 HIGH
BAN Users < 1.5.3 - Authenticated Privilege Escalation via Missing Capability Check
CVSS 8.8
Details
Vulnerabilities 926