CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

814 vulnerabilities with CWE-266
CVE-2026-3667 MEDIUM
Freedom Factory dGEN1 <20260221 - Privilege Escalation
CVSS 5.3
CVE-2026-27983 CRITICAL
LMS Elementor Pro <=1.0.4 - Privilege Escalation
CVSS 9.8
CVE-2026-27541 HIGH
Wholesale Suite <=2.2.6 - Privilege Escalation
CVSS 7.2
CVE-2026-24963 HIGH
Amelia ameliabooking <=1.2.38 - Privilege Escalation
CVSS 7.2
CVE-2026-21425 MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2026-0871 MEDIUM
Keycloak - Privilege Escalation
CVSS 4.9
CVE-2026-3268 MEDIUM
psi-probe PSI Probe <=5.3.0 - Auth Bypass
CVSS 5.4
CVE-2026-3265 MEDIUM
go2ismail Free-CRM - Auth Bypass
CVSS 6.3
CVE-2026-3263 MEDIUM
Asp.Net-Core-Inventory-Order-Management-System <9.20250118 - Auth B...
CVSS 6.3
CVE-2026-3209 MEDIUM
fosrl Pangolin <1.15.4-s.3 - Auth Bypass
CVSS 6.3
CVE-2026-2983 HIGH
Student Result Management System 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-2938 HIGH
Student Result Management System 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-2896 HIGH
funadmin <7.1.0-rc4 - Privilege Escalation
CVSS 7.3
CVE-2026-2860 MEDIUM
feng_ha_ha/megagao ssm-erp - Auth Bypass
CVSS 6.3
CVE-2026-2852 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2851 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2850 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2849 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 5.4
CVE-2026-22268 MEDIUM
Dell PowerProtect Data Manager <19.22 - Privilege Escalation
CVSS 6.3
CVE-2026-22267 HIGH
Dell PowerProtect Data Manager <19.22 - Privilege Escalation
CVSS 8.1
CVE-2026-2693 MEDIUM
CoCoTeaNet CyreneAdmin <1.3.0 - Auth Bypass
CVSS 4.3
CVE-2026-2676 MEDIUM
GoogTech sms-ssm - Auth Bypass
CVSS 6.3
CVE-2026-2669 MEDIUM
Rongzhitong Visual Platform - Auth Bypass
CVSS 6.5
CVE-2026-2668 HIGH
Rongzhitong Visual Platform - Auth Bypass
CVSS 7.3
CVE-2026-2667 MEDIUM
Rongzhitong Visual Platform - Auth Bypass
CVSS 5.3
Details
Vulnerabilities 814