CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

1,014 vulnerabilities with CWE-266
CVE-2026-12780 HIGH
AOMEI Backupper Kernel Driver amwrtdrv.sys access control
CVSS 7.8
CVE-2026-12779 HIGH
AOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access control
CVSS 7.8
CVE-2026-12778 HIGH
AOMEI Partition Assistant Kernel Driver ampa10.sys access control
CVSS 7.8
CVE-2026-12771 MEDIUM
BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
CVSS 5.0
CVE-2026-12770 MEDIUM
BerriAI litellm Admin Key key_management_endpoints.py improper authorization
CVSS 5.4
CVE-2026-12529 HIGH
SourceCodester CET Automated Grading System with AI Predictive Analytics Student Self-Registration Endpoint index.php access control
CVSS 7.3
CVE-2026-54807 CRITICAL
WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-54805 HIGH
WordPress Falang multilanguage plugin <= 1.4.2 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-54196 MEDIUM
WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability
CVSS 6.8
CVE-2026-49058 CRITICAL
WordPress LoginPress Pro plugin <= 6.2.2 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-39546 HIGH
WordPress MultiLoca plugin <= 4.2.15 - Privilege Escalation vulnerability
CVSS 7.6
CVE-2026-27395 CRITICAL
WordPress Support Board plugin < 3.8.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-53862 MEDIUM
OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening
CVSS 4.2
CVE-2026-53847 MEDIUM
OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope
CVSS 5.4
CVE-2026-12294 CRITICAL
Sandbox escape in the DOM: Workers component
CVSS 9.6
CVE-2026-12289 HIGH
Privilege escalation in the Graphics: WebRender component
CVSS 8.8
CVE-2026-49780 HIGH
WordPress Dokan plugin <= 5.0.2 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-49083 HIGH
WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability
CVSS 7.5
CVE-2026-49063 HIGH
WordPress Listdom plugin <= 5.5.0 - Privilege Escalation vulnerability
CVSS 7.3
CVE-2026-48889 HIGH
WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-39587 HIGH
WordPress WP BASE Booking plugin <= 5.9.0 - Privilege Escalation vulnerability
CVSS 8.1
CVE-2026-39583 CRITICAL
WordPress Datalogics Ecommerce Delivery plugin <= 2.6.62 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-39579 HIGH
WordPress B Blocks plugin <= 2.0.31 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-39470 HIGH
WordPress WooCommerce Cart Abandonment Recovery plugin < 2.1.0 - Privilege Escalation vulnerability
CVSS 7.2
CVE-2026-34901 CRITICAL
WordPress iControlWP plugin <= 5.5.3 - Privilege Escalation vulnerability
CVSS 9.8
Details
Vulnerabilities 1,014