CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

1,014 vulnerabilities with CWE-266
CVE-2026-11462 HIGH
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
CVSS 7.3
CVE-2026-11441 MEDIUM
theonedev Pull Request issues canAccessIssue improper authorization
CVSS 6.3
CVE-2026-11440 MEDIUM
theonedev REST API default-branch improper authorization
CVSS 6.3
CVE-2026-11439 MEDIUM
theonedev Parent Project projects improper authorization
CVSS 6.3
CVE-2026-11438 MEDIUM
theonedev projects improper authorization
CVSS 6.3
CVE-2026-11336 MEDIUM
tittuvarghese CollegeManagementSystem Admin admin_page.php improper authorization
CVSS 6.3
CVE-2026-10876 MEDIUM
SourceCodester Ship Ferry Ticket Reservation System admin improper authorization
CVSS 6.3
CVE-2026-10693 MEDIUM
SourceCodester Online Boat Reservation System Administrative Endpoint improper authorization
CVSS 6.3
CVE-2026-10294 MEDIUM
PackageKit <= 1.3.5 - Improper Authorization via Frontend-Socket Argument
CVSS 4.3
CVE-2026-10285 MEDIUM
DevaslanPHP project-management <= 2.0.0-beta1 - Improper Authorization in KanbanScrumHelper Ticket Handler
CVSS 5.4
CVE-2026-10284 MEDIUM
DevaslanPHP project-management <= 2.0.0-beta1 - Incorrect Privilege Assignment in Livewire Handler
CVSS 5.4
CVE-2026-10282 MEDIUM
Bottelet DaybydayCRM <= 2.2.1 - Incorrect Privilege Assignment in DocumentsController
CVSS 4.3
CVE-2026-10277 MEDIUM
j3k0 mcp-google-workspace - Incorrect Privilege Assignment in Gmail Tool saveToDisk Function
CVSS 6.3
CVE-2026-10272 MEDIUM
a4m4 Student-Management-System deleteform.php improper authorization
CVSS 6.5
CVE-2026-10269 MEDIUM
decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization
CVSS 6.3
CVE-2026-48879 CRITICAL
WordPress AIWU plugin <= 1.4.17 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-42680 CRITICAL
WordPress Contest Gallery Pro plugin <= 29.0.1 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-10255 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ShowForm.php sell_statement access control
CVSS 5.3
CVE-2026-10236 HIGH
SourceCodester Water Billing Management System User Management Endpoint Users.php save improper authorization
CVSS 7.3
CVE-2026-10218 MEDIUM
nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization
CVSS 5.4
CVE-2026-10217 MEDIUM
nextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges management
CVSS 6.3
CVE-2026-10215 MEDIUM
Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorization
CVSS 4.3
CVE-2026-10152 MEDIUM
TaleLin lin-cms-spring-boot book Endpoint BookController.java access control
CVSS 6.3
CVE-2026-10070 MEDIUM
macrozheng mall Super Admin Password update improper authorization
CVSS 4.7
CVE-2026-43000 MEDIUM
Openstack Keystone - Incorrect Authorization
CVSS 6.0
Details
Vulnerabilities 1,014