CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

1,014 vulnerabilities with CWE-266
CVE-2026-27407 HIGH
WordPress AI Engine plugin <= 3.4.9 - Privilege Escalation vulnerability
CVSS 7.2
CVE-2026-49111 HIGH
WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-12217 HIGH
DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
CVSS 7.8
CVE-2026-12213 MEDIUM
hcengineering Huly Platform User Information operations.ts getAccountInfo improper authorization
CVSS 4.3
CVE-2026-12212 MEDIUM
hcengineering Huly Platform RPC operations.ts getMailboxSecret access control
CVSS 4.3
CVE-2026-12201 MEDIUM
IObit Malware Fighter DLL permission
CVSS 5.3
CVE-2026-44173 MEDIUM
MariaDB: FILE privilege was not checked for subqueries in the FROM clause
CVSS 5.0
CVE-2026-45830 HIGH
ChromaDB - Authorization Bypass Through User-Controlled Key
CVSS 8.8
CVE-2026-49060 CRITICAL
WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-53814 HIGH
OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool Authority
CVSS 8.3
CVE-2026-47169 HIGH
Quest Bot: Manage Server users can configure AutoRole to grant Administrator to controlled joining accounts
CVE-2026-45490 HIGH
Microsoft .NET - Local Privilege Escalation
CVSS 7.8
CVE-2026-11620 MEDIUM
TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation
CVSS 5.3
CVE-2026-11619 MEDIUM
Dolibarr ERP CRM Legacy Filemanager config.inc.php improper authorization
CVSS 6.3
CVE-2026-11555 LOW
D-Link DGS-1100-08PD Web boa.conf least privilege violation
CVSS 3.7
CVE-2026-11554 MEDIUM
TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation
CVSS 4.3
CVE-2026-11533 MEDIUM
imvks786 student_management_system Student Deletion Endpoint see.php improper authorization
CVSS 5.4
CVE-2026-11532 MEDIUM
imvks786 student_management_system Student Record add.php access control
CVSS 6.3
CVE-2026-11521 MEDIUM
Mohammed-eid35 bank-management-system-springboot Transaction Endpoint TransactionController.java improper authorization
CVSS 6.3
CVE-2026-11519 MEDIUM
SourceCodester Inventory System Account Creation users_handler.php improper authorization
CVSS 6.3
CVE-2026-11497 MEDIUM
D-Link DCS-5615 Boa Webserver boa.conf least privilege violation
CVSS 5.3
CVE-2026-11494 MEDIUM
TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation
CVSS 4.3
CVE-2026-11492 MEDIUM
D-Link DIR-823G vsftpd vsftpd.conf least privilege violation
CVSS 4.3
CVE-2026-11476 MEDIUM
Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization
CVSS 6.3
CVE-2026-11466 MEDIUM
zilliztech deep-searcher collection_router.py CollectionRouter.invoke access control
CVSS 5.4
Details
Vulnerabilities 1,014