CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

815 vulnerabilities with CWE-266
CVE-2025-13808 HIGH
Orionsec Orion-ops < 2025-08-01 - Improper Authorization
CVSS 7.3
CVE-2025-13807 MEDIUM
Orionsec Orion-ops < 2025-08-01 - Improper Authorization
CVSS 4.3
CVE-2025-13806 HIGH
Nutzam Nutzboot < 2.6.0 - Incorrect Authorization
CVSS 7.3
CVE-2025-13787 MEDIUM
Zentao < 21.7.7 - Improper Privilege Management
CVSS 5.4
CVE-2025-45311 HIGH
fail2ban-client v0.11.2 - Privilege Escalation
CVSS 8.8
CVE-2025-64761 HIGH
Openbao < 2.4.4 - Incorrect Privilege Assignment
CVSS 7.2
CVE-2025-13576 MEDIUM
Fabian Blog Site - Improper Authorization
CVSS 6.3
CVE-2025-0504 MEDIUM
Black Duck SCA <2025.10.0 - Privilege Escalation
CVSS 5.4
CVE-2025-41115 CRITICAL
Grafana < 12.2.1 - Incorrect Privilege Assignment
CVSS 10.0
CVE-2025-13443 MEDIUM
Macrozheng Mall < 1.0.3 - Improper Access Control
CVSS 5.4
CVE-2025-65094 HIGH
Wbce Cms < 1.6.4 - Improper Authorization
CVSS 8.8
CVE-2025-13250 MEDIUM
Datax-web < 2.1.2 - Improper Access Control
CVSS 6.3
CVE-2025-13131 HIGH
Sonarr 4.0.15.2940 - Local Privilege Escalation
CVSS 7.8
CVE-2025-13130 HIGH
Radarr 5.28.0.10274 - Privilege Escalation
CVSS 7.8
CVE-2025-13118 MEDIUM
Macrozheng Mall < 1.0.3 - Improper Authorization
CVSS 6.3
CVE-2025-13117 MEDIUM
Macrozheng Mall < 1.0.3 - Improper Authorization
CVSS 5.4
CVE-2025-13116 MEDIUM
Macrozheng Mall < 1.0.3 - Improper Authorization
CVSS 5.4
CVE-2025-13115 MEDIUM
Macrozheng Mall < 1.0.3 - Improper Authorization
CVSS 4.3
CVE-2025-13114 MEDIUM
Macrozheng Mall-swarm < 1.0.3 - Improper Authorization
CVSS 6.3
CVE-2025-2843 HIGH
Rhobs Observability-operator < 1.3.0 - Incorrect Privilege Assignment
CVSS 8.8
CVE-2025-63384 MEDIUM
RISC-V Rocket-Chip <1.6 - Privilege Escalation
CVSS 6.5
CVE-2025-56503 MEDIUM
Sublime Text 4 4200 - Privilege Escalation
CVSS 6.5
CVE-2025-6325 CRITICAL
King Addons for Elementor <51.1.36 - Privilege Escalation
CVSS 9.8
CVE-2025-62034 HIGH
uxper Togo <1.0.4 - Privilege Escalation
CVSS 8.8
CVE-2025-60243 CRITICAL
Holest Engineering Selling Commander - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 815