CWE-266: Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
1,061 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-28000 — WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
- CVE-2024-24882 — WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
- CVE-2026-48172 — LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild i
- CVE-2024-22145 — WordPress InstaWP Connect plugin <= 0.1.0.8 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2025-27007 — WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
- CVE-2026-23550 — WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
- CVE-2026-23800 — WordPress Modular DS plugin <= 2.5.2 - Privilege Escalation vulnerability
- CVE-2025-47539 — WordPress Eventin <= 4.0.26 - Privilege Escalation Vulnerability
- CVE-2025-2345 — IROAD Dash Cam X5/Dash Cam X6 improper authorization
- CVE-2024-9479 — Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc
- CVE-2024-9478 — Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc
- CVE-2026-22907 — An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system dat
- CVE-2025-62645 — The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker t
- CVE-2025-54049 — WordPress Custom API for WP <= 4.2.2 - Privilege Escalation Vulnerability
- CVE-2025-26512 — CVE-2025-26512 Privilege Escalation Vulnerability in SnapCenter
- CVE-2025-10725 — Openshift-ai: overly permissive clusterrole allows authenticated users to escalate privileges to cluster admin
- CVE-2025-53580 — WordPress Simple Business Directory Pro Plugin < 15.6.9 - Privilege Escalation Vulnerability
- CVE-2025-52836 — WordPress The E-Commerce ERP <= 2.1.1.3 - Privilege Escalation Vulnerability
- CVE-2025-49867 — WordPress RealHomes <= 4.4.0 - Privilege Escalation Vulnerability
- CVE-2025-49388 — WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
Recently published
- CVE-2026-15140 — A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific cond
- CVE-2026-86804 — seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
- CVE-2026-77654 — Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
- CVE-2026-85400 — TYPO3 CMS - Missing Authorization in lowlevel commands
- CVE-2026-81792 — WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privilege Escalation vulnerability
- CVE-2026-86516 — elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management
- CVE-2026-86512 — java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control
- CVE-2026-86500 — In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant th
- CVE-2026-86482 — In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
- CVE-2026-86285 — BookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm access control
- CVE-2026-86275 — SourceCodester Syllabus-Aligned Learning Management & Examination System auth.php register privileges management
- CVE-2026-86228 — JeecgBoot AiragModelController.java exportXls access control
- CVE-2026-86212 — Open5GS AMF/MME improper authorization
- CVE-2026-86153 — Tenda CP3 Redirect.cpp SetRedirectEnable privileges management
- CVE-2026-85514 — StackStorm st2 API Key auth.py privileges management
- CVE-2026-85513 — StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management
- CVE-2026-85401 — Dolibarr Legacy File Manager config.inc.php access control
- CVE-2026-85241 — SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization
- CVE-2026-84814 — WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability
- CVE-2026-84756 — WordPress WCFM Membership plugin <= 2.11.11 - Privilege Escalation vulnerability
More specific weaknesses
- CWE-1022 — Use of Web Link to Untrusted Target with window.opener Access
- CWE-1268 — Policy Privileges are not Assigned Consistently Between Control and Data Agents
- CWE-520 — .NET Misconfiguration: Use of Impersonation
- CWE-556 — ASP.NET Misconfiguration: Use of Identity Impersonation
- CWE-9 — J2EE Misconfiguration: Weak Access Permissions for EJB Methods