CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

1,014 vulnerabilities with CWE-266
CVE-2026-35671 HIGH
phpMyFAQ - Insecure Direct Object Reference in User Password API
CVSS 8.8
CVE-2026-9795 HIGH
Keycloak: keycloak: privilege escalation via improper scope mapping enforcement
CVSS 7.3
CVE-2026-42758 CRITICAL
WordPress WebinarIgnition plugin < 4.08.253 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-42731 CRITICAL
WordPress miniorange otp verification plugin <= 5.4.9 - Privilege Escalation vulnerability
CVSS 9.8
CVE-2026-9604 MEDIUM
JeecgBoot AiragModelController access control
CVSS 4.3
CVE-2026-9581 MEDIUM
JeecgBoot add access control
CVSS 6.3
CVE-2026-9580 HIGH
JeecgBoot selectDepart LoginController.selectDepart access control
CVSS 7.3
CVE-2026-9579 MEDIUM
JeecgBoot SysUser userEdit user.getUsername access control
CVSS 6.3
CVE-2026-9562 HIGH
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
CVSS 7.3
CVE-2026-9517 HIGH
hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control
CVSS 7.3
CVE-2026-45216 HIGH
WordPress Smart Manager plugin <= 8.85.0 - Privilege Escalation vulnerability
CVSS 8.8
CVE-2026-9484 MEDIUM
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
CVSS 6.3
CVE-2026-9483 MEDIUM
SourceCodester Student Grades Management System grades.php improper authorization
CVSS 6.3
CVE-2026-9412 MEDIUM
SourceCodester Indian Invoicing System Backend Endpoint access control
CVSS 6.3
CVE-2026-9410 MEDIUM
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
CVSS 4.3
CVE-2026-9409 MEDIUM
Sushmi-pal Invoice-System User Management user improper authorization
CVSS 4.3
CVE-2026-9397 HIGH
Besen BS20 EV Charging Station OTA Update Installation improper authorization
CVSS 8.1
CVE-2026-9376 MEDIUM
JPress UCenter Article Submission Endpoint doWriteSave improper authorization
CVSS 6.3
CVE-2026-48172 CRITICAL KEV
LiteSpeed cPanel Plugin < 2.4.5 - Privilege Escalation via Redis Feature Mishandling
CVSS 9.8
CVE-2026-22315 HIGH
Mesalvo Meona Client Launcher <= 19.06.2020 & Server <= 2025.04 - Unprotected User Data Exposure
CVSS 7.2
CVE-2026-8752 MEDIUM
h2oai h2o-3 Rapids setproperty Primitive AstSetProperty.java exec access control
CVSS 5.3
CVE-2026-8747 MEDIUM
Z-BlogPHP Commend Approval c_system_event.php CheckComment improper authorization
CVSS 6.3
CVE-2026-8743 MEDIUM
Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorization
CVSS 6.3
CVE-2026-35062 MEDIUM
F5 BIG-IP 21.1.0-21.0.0.1/17.5.1-17.5.1.4/17.1.0-17.1.3.1/16.1.0 Authenticated Info Disclosure via iControl SOAP
CVSS 6.5
CVE-2026-44997 MEDIUM
OpenClaw < 2026.4.22 - Security Envelope Constraint Bypass in ACP Child Sessions
CVSS 4.3
Details
Vulnerabilities 1,014