CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

926 vulnerabilities with CWE-266
CVE-2023-21269 HIGH
Android - Local Privilege Escalation via Background Activity PiP Mode Bypass
CVSS 7.8
CVE-2023-30691 HIGH
Samsung Android - Privilege Escalation via Parcel Mismatch in AuthenticationConfig
CVSS 8.4
CVE-2023-30680 HIGH
Samsung Android - Incorrect Privilege Assignment in MMIGroup
CVSS 8.4
CVE-2023-3518 HIGH
HashiCorp Consul <1.16.1 - Privilege Escalation
CVSS 7.4
CVE-2023-39173 MEDIUM
JetBrains TeamCity <2023.05.2 - Privilege Escalation
CVSS 5.4
CVE-2023-3300 MEDIUM
HashiCorp Nomad <1.5.6-1.4.1 - Info Disclosure
CVSS 5.3
CVE-2023-3072 MEDIUM
HashiCorp Nomad <1.5.6-1.4.10 - Info Disclosure
CVSS 4.1
CVE-2023-3114 MEDIUM
Terraform Enterprise <202306-1 - Privilege Escalation
CVSS 5.0
CVE-2023-28956 HIGH
IBM Spectrum Protect Backup-Archive Client <8.1.17.2 - Privilege Es...
CVSS 8.4
CVE-2023-2485 MEDIUM
GitLab 14.1-15.10.7, 15.11-15.11.6, 16.0-16.0.1 - Incorrect Privilege Assignment via Project Member Import
CVSS 4.4
CVE-2023-2816 HIGH
Consul 1.15.0-1.15.3 - Incorrect Privilege Assignment via Envoy Extension Downstream Proxy Configuration
CVSS 8.7
CVE-2023-1174 CRITICAL
minikube - Unauthenticated Unexpected Remote Access via Exposed Network Port
CVSS 9.8
CVE-2023-1874 HIGH
WP Data Access <5.3.7 - Privilege Escalation
CVSS 7.5
CVE-2023-20957 HIGH
Android - Local Privilege Escalation via SettingsPreferenceFragment Confused Deputy
CVSS 7.8
CVE-2023-25591 HIGH
ClearPass Policy Manager - Authenticated Information Disclosure via Web Management Interface
CVSS 7.6
CVE-2022-50927 MEDIUM
Cyclades Serial Console Server 3.3.0 - Privilege Escalation
CVSS 6.2
CVE-2022-4441 HIGH
Hitachi Storage Plug-in for VMware vCenter 04.9.0 - Authenticated Privilege Escalation
CVSS 7.6
CVE-2022-4041 MEDIUM
Hitachi Storage Plug-in for VMware vCenter <4.9.1 - Privilege Escal...
CVSS 5.9
CVE-2022-4613 MEDIUM
Click Studios Passwordstate - Auth Bypass
CVSS 5.0
CVE-2022-3876 MEDIUM
Click Studios Passwordstate - Auth Bypass
CVSS 4.3
CVE-2022-4281 MEDIUM
Facepay 1.0 - Authorization Bypass via userId Parameter
CVSS 6.3
CVE-2022-4280 MEDIUM
Dot Tech Smart Campus System - Information Disclosure via findUser Endpoint
CVSS 4.3
CVE-2022-4276 MEDIUM
House Rental System - Unrestricted File Upload via tenant-engine.php id_photo Parameter
CVSS 6.3
CVE-2022-4273 HIGH
SourceCodester Human Resource Management System 1.0 - Unrestricted File Upload via pfimg Argument
CVSS 7.3
CVE-2022-4272 MEDIUM
Warehouse Management System - Unrestricted File Upload
CVSS 6.3
Details
Vulnerabilities 926