CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

815 vulnerabilities with CWE-266
CVE-2025-15087 MEDIUM
Youlai-mall - Improper Authorization
CVSS 4.3
CVE-2025-15086 MEDIUM
Youlai-mall - Improper Access Control
CVSS 4.3
CVE-2025-15085 MEDIUM
Youlai-mall - Incorrect Authorization
CVSS 4.3
CVE-2025-15084 LOW
Youlai-mall - Improper Access Control
CVSS 3.1
CVE-2025-14889 MEDIUM
Campcodes Advanced Voting Management System - Improper Authorization
CVSS 5.4
CVE-2025-64188 CRITICAL
PenciDesign Soledad <=8.6.9 - Privilege Escalation
CVSS 9.8
CVE-2025-59134 HIGH
Sale! Immigration law - Privilege Escalation
CVSS 8.8
CVE-2025-58710 HIGH
e-plugins Hotel Listing <1.4.0 - Privilege Escalation
CVSS 8.8
CVE-2025-55707 HIGH
WPXPO PostX <4.1.35 - Privilege Escalation
CVSS 7.2
CVE-2025-49379 HIGH
silverplugins217 Custom Fields Account Registration For Woocommerce...
CVSS 7.2
CVE-2025-14749 MEDIUM
Shenzhenningyuandatechnology Tc155 Firmware - Improper Access Control
CVSS 6.3
CVE-2025-14748 MEDIUM
Shenzhenningyuandatechnology Tc155 Firmware - Improper Access Control
CVSS 5.4
CVE-2025-14503 HIGH
Harmonix on AWS <0.4.2 - Privilege Escalation
CVSS 7.2
CVE-2025-13888 CRITICAL
Redhat-developer Gitops-operator - Incorrect Privilege Assignment
CVSS 9.1
CVE-2025-14660 MEDIUM
DecoCMS Mesh <1.0.0-alpha.31 - Improper Access Control
CVSS 5.6
CVE-2025-65807 HIGH
sd command <1.0.0 - Privilege Escalation
CVSS 8.4
CVE-2025-14206 MEDIUM
SourceCodester Online Student Clearance System 1.0 - Auth Bypass
CVSS 6.5
CVE-2025-14089 MEDIUM
Himool ERP <2.2 - Privilege Escalation
CVSS 6.3
CVE-2025-14088 MEDIUM
ketr JEPaaS <7.2.8 - Auth Bypass
CVSS 6.3
CVE-2025-14086 MEDIUM
Youlai-mall - Improper Access Control
CVSS 6.3
CVE-2025-14052 MEDIUM
Youlai-mall - Improper Access Control
CVSS 6.3
CVE-2025-55948 HIGH
X-SpringBoot 6.0 - SSRF
CVSS 7.3
CVE-2025-14016 MEDIUM
Macrozheng Mall-swarm < 1.0.3 - Incorrect Authorization
CVSS 5.4
CVE-2025-65842 MEDIUM
Aquarius HelperTool 1.0.003 - Privilege Escalation
CVSS 5.1
CVE-2025-66296 HIGH
Grav <1.8.0-beta.27 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 815