CWE-266
1,010 CVEs • Abstraction: Base
Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CVEs (1,010)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bosch 1Smart Home Controller Firmware Jun 17, 2026 May 29, 2019 N/A· v4 8.0 HIGH· v3 5.4 MEDIUM· v2 A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In...Show more |
3Fedoraproject FreeradiusRedhat3Enterprise Linux FedoraFreeradiusJun 17, 2026 May 24, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by trickin...Show more |
4Canonical FedoraprojectNetapp+1 more7Cn1610 Firmware FedoraHci Management Node+4 moreJun 17, 2026 Apr 26, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker m...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Sep 11, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary opera...Show more |
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to g...Show more |
1Redhat 2Ansible Tower CloudformsNov 21, 2024 May 2, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passw...Show more |
3Debian OpensuseRedhat6Debian Linux Enterprise Linux ServerGluster Storage+3 moreNov 21, 2024 Apr 18, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious...Show more |
An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that may allow a user to elevate to administra...Show more |
2Openbsd Oracle2Communications User Data Repository OpensshMay 28, 2026 Mar 18, 2014 N/A· v4 4.9 MEDIUM· v3 5.8 MEDIUM· v2 sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard c...Show more |
1Redhat 1Jboss Enterprise Application Platform May 14, 2026 Jan 5, 2013 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are...Show more |