CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

914 vulnerabilities with CWE-266
CVE-2026-3268 MEDIUM
psi-probe PSI Probe <=5.3.0 - Auth Bypass
CVSS 5.4
CVE-2026-3265 MEDIUM
go2ismail free-crm < 2025-09-21 - Improper Authorization in Security API
CVSS 6.3
CVE-2026-3263 MEDIUM
Asp.Net-Core-Inventory-Order-Management-System <9.20250118 - Auth B...
CVSS 6.3
CVE-2026-3209 MEDIUM
fosrl Pangolin <1.15.4-s.3 - Auth Bypass
CVSS 6.3
CVE-2026-2983 HIGH
Student Result Management System 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-2938 HIGH
Student Result Management System 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-2896 HIGH
funadmin <7.1.0-rc4 - Privilege Escalation
CVSS 7.3
CVE-2026-2860 MEDIUM
feng_ha_ha/megagao ssm-erp - Auth Bypass
CVSS 6.3
CVE-2026-2852 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2851 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2850 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2849 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 5.4
CVE-2026-22268 MEDIUM
Dell PowerProtect Data Manager <19.22 - Privilege Escalation
CVSS 6.3
CVE-2026-22267 HIGH
Dell PowerProtect Data Manager <19.22 - Privilege Escalation
CVSS 8.1
CVE-2026-2693 MEDIUM
CoCoTeaNet CyreneAdmin <1.3.0 - Auth Bypass
CVSS 4.3
CVE-2026-2676 MEDIUM
GoogTech sms-ssm - Improper Authorization in LoginInterceptor API Interface
CVSS 6.3
CVE-2026-2669 MEDIUM
Rongzhitong Visual Platform - Auth Bypass
CVSS 6.5
CVE-2026-2668 HIGH
Rongzhitong Visual Platform - Auth Bypass
CVSS 7.3
CVE-2026-2667 MEDIUM
Rongzhitong Visual Platform - Auth Bypass
CVSS 5.3
CVE-2026-2563 MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-2562 MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-2561 MEDIUM
JingDong JD Cloud Box AX6600 <4.5.1.r4533 - Remote Privilege Escala...
CVSS 6.3
CVE-2026-2549 HIGH
LibrarySystem 图书馆管理系统 <1.1.1 - Auth Bypass
CVSS 7.3
CVE-2026-2141 MEDIUM
WuKongOpenSource WukongCRM <11.3.3 - Auth Bypass
CVSS 6.3
CVE-2026-2209 MEDIUM
Wekan < 8.19 - Incorrect Privilege Assignment in Custom Translation Handler
CVSS 6.3
Details
Vulnerabilities 914