CWE-266— Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
1,005 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-266page 17 of 21
- CVE-2026-20852HIGHCVSS 7.7EG 7.72026-01-13
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
- CVE-2026-2105MEDIUMCVSS 6.3EG 6.32026-02-07
A flaw has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The affected element is the function addDept/updateDept/deleteDept of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\DeptCo…
- CVE-2026-2106MEDIUMCVSS 6.3EG 6.32026-02-07
A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/deleteNotice/batchDeleteNotice of the file dataset\repos\warehouse\src\main\java…
- CVE-2026-2107MEDIUMCVSS 6.3EG 6.32026-02-07
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDeleteLoginfo of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\contro…
- CVE-2026-2109MEDIUMCVSS 5.4EG 5.42026-02-07
A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. T…
- CVE-2026-2141HIGHCVSS 8.8EG 8.82026-02-08
A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Perfo…
- CVE-2026-21824HIGHCVSS 8.8EG 8.82026-07-20
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
- CVE-2026-2206MEDIUMCVSS 6.3EG 6.32026-02-08
A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation results in improper …
- CVE-2026-22078HIGHCVSS 7.3EG 7.32026-06-29
Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.
- CVE-2026-2209MEDIUMCVSS 6.3EG 6.32026-02-08
A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in …
- CVE-2026-22315HIGHCVSS 7.2EG 7.22026-05-20
Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export of user data, including cleartext passwords, via the SQL editor. This issue affects Meona Client …
- CVE-2026-22337CRITICALCVSS 9.8EG 9.82026-04-27
Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4.
- CVE-2026-22907CRITICALCVSS 9.9EG 9.92026-01-15
An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.
- CVE-2026-22908CRITICALCVSS 9.1EG 9.12026-01-15
Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.
- CVE-2026-22914MEDIUMCVSS 4.3EG 4.32026-01-15
An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.
- CVE-2026-22916MEDIUMCVSS 4.3EG 4.32026-01-15
An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.
- CVE-2026-23550CRITICALCVSS 9.8EG 10.02026-01-14
Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.
- CVE-2026-23800CRITICALCVSS 10.0EG 10.02026-01-16
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.
- CVE-2026-24373HIGHCVSS 8.1EG 8.12026-03-25
Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1.
- CVE-2026-24963HIGHCVSS 7.2EG 7.22026-03-05
Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38.
- CVE-2026-24968CRITICALCVSS 9.8EG 9.82026-03-25
Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.
- CVE-2026-24971CRITICALCVSS 9.8EG 9.82026-03-25
Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.
- CVE-2026-25334HIGHCVSS 8.1EG 8.12026-03-25
Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12.
- CVE-2026-25414HIGHCVSS 8.8EG 8.82026-03-25
Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18.
- CVE-2026-2549HIGHCVSS 7.3EG 7.32026-02-16
A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls. The attack is possible to…
- CVE-2026-2561MEDIUMCVSS 6.3EG 6.32026-02-16
A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Performing a manipulation results in Remote Privilege Escalation. T…
- CVE-2026-2562MEDIUMCVSS 6.3EG 6.32026-02-16
A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the component jdcweb_rpc. Executing a manipulation of the argument File can lead to Remote Privi…
- CVE-2026-2563MEDIUMCVSS 6.3EG 6.32026-02-16
A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDevice of the component jdcapp_rpc. The manipulation leads to …
- CVE-2026-26053MEDIUMCVSS 5.3EG 5.32026-07-07
An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Versio…
- CVE-2026-2668HIGHCVSS 7.3EG 7.32026-02-18
A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handler. The manipulation results in improper…
- CVE-2026-2669MEDIUMCVSS 6.5EG 6.52026-02-18
A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the arg…
- CVE-2026-2676MEDIUMCVSS 6.3EG 6.32026-02-18
A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle of the file LoginInterceptor.java of the component API Interface. Executing a manipulation …
- CVE-2026-2693MEDIUMCVSS 4.3EG 4.32026-02-19
A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCount of the component System Info Endpoint. Executing a manipulation can lead to improper a…
- CVE-2026-27051CRITICALCVSS 9.8EG 9.82026-03-25
Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.
- CVE-2026-27102MEDIUMCVSS 6.6EG 6.62026-04-08
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulner…
- CVE-2026-27395CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
- CVE-2026-27407HIGHCVSS 7.2EG 7.22026-06-15
Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
- CVE-2026-27541HIGHCVSS 7.2EG 7.22026-03-05
Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.6.
- CVE-2026-27542CRITICALCVSS 9.8EG 9.82026-03-19
Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a throug…
- CVE-2026-27668HIGHCVSS 8.8EG 8.82026-04-14
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrato…
- CVE-2026-27983CRITICALCVSS 9.8EG 9.82026-03-05
Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS Elementor Pro: from n/a through <= 1.0.4.
- CVE-2026-2849MEDIUMCVSS 5.4EG 5.42026-02-20
A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function deleteCache/removeAllCache/syncCache of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys…
- CVE-2026-2850MEDIUMCVSS 6.3EG 6.32026-02-20
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\C…
- CVE-2026-2851MEDIUMCVSS 6.3EG 6.32026-02-20
A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability affects the function addInport/updateInport/deleteInport of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus…
- CVE-2026-2852MEDIUMCVSS 6.3EG 6.32026-02-20
A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSales/deleteSales of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller…
- CVE-2026-2860MEDIUMCVSS 6.3EG 6.32026-02-21
A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted is an unknown function of the file EmployeeController.java. The manipulation leads to impr…
- CVE-2026-2896HIGHCVSS 7.3EG 7.32026-02-22
A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization…
- CVE-2026-2938HIGHCVSS 7.3EG 7.32026-02-22
A vulnerability has been found in SourceCodester Student Result Management System 1.0. The affected element is an unknown function of the file /srms/script/admin/core/update_smtp.php. The manipulation leads to improper access controls. It …
- CVE-2026-2983HIGHCVSS 7.3EG 7.32026-02-23
A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument Fil…
- CVE-2026-3209MEDIUMCVSS 6.3EG 6.32026-02-25
A vulnerability has been found in fosrl Pangolin up to 1.15.4-s.3. This affects the function verifyRoleAccess/verifyApiKeyRoleAccess of the component Role Handler. The manipulation leads to improper access controls. Remote exploitation of …
Map vulnerabilities like CWE-266 to your infrastructure
EchelonGraph correlates every CVE — across CWE-266 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →