← Back
CWE-266

1,010 CVEs • Abstraction: Base

Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

JSON object

Loading...

CVEs (1,010)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chamilo
1Chamilo Lms
Jun 17, 2026
Jan 18, 2026
2.1 LOW· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of the component Legal Consent Handler. Perfor...Show more
A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of the component Legal Consent Handler. Performing a manipulation of the argument userId results in improper authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Jun 17, 2026
Jan 16, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.
-
-
Jun 17, 2026
Jan 15, 2026
8.5 HIGH· v4
6.2 MEDIUM· v3
N/A· v2
Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root access. Attackers can exploit the unsafe Sudo settings by using mount...Show more
Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root access. Attackers can exploit the unsafe Sudo settings by using mount commands to bind a shell, enabling unauthorized system-level privileges.Show less
1Sick
1Tdc X401gl Firmware
Jun 17, 2026
Jan 15, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.
1Sick
1Tdc X401gl Firmware
Jun 17, 2026
Jan 15, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.
1Sick
1Tdc X401gl Firmware
Jun 17, 2026
Jan 15, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.
1Sick
1Tdc X401gl Firmware
Jun 17, 2026
Jan 15, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.
-
-
Jun 17, 2026
Jan 14, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.
-
-
Jun 17, 2026
Jan 13, 2026
8.5 HIGH· v4
6.2 MEDIUM· v3
N/A· v2
Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration t...Show more
Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted sudo permissions.Show less
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jun 17, 2026
Jan 13, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jun 17, 2026
Jan 13, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
1Tim Solutions
1Tim Flow
Jun 17, 2026
Jan 9, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format
1Tim Solutions
1Tim Flow
Jun 17, 2026
Jan 9, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request
-
-
Jun 17, 2026
Jan 7, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPCHURCH: from n/a through 2.7.0.
-
-
Jun 17, 2026
Jan 6, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issu...Show more
Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0.Show less
1Yeqifu
1Warehouse
Jun 17, 2026
Jan 4, 2026
2.1 LOW· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java...Show more
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java of the component Request Handler. This manipulation causes improper authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.Show less
1Fabian
1Student File Management System
Jun 17, 2026
Dec 30, 2025
2.1 LOW· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the ar...Show more
A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the argument store_id leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.Show less
1Jeecg
1Jeecg Boot
Jun 17, 2026
Dec 28, 2025
1.3 LOW· v4
7.5 HIGH· v3
2.1 LOW· v2
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId caus...Show more
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Jeecg
1Jeecg Boot
Jun 17, 2026
Dec 28, 2025
1.3 LOW· v4
3.1 LOW· v3
2.1 LOW· v2
A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument departId results in imprope...Show more
A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument departId results in improper authorization. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Jeecg
1Jeecg Boot
Jun 17, 2026
Dec 28, 2025
1.3 LOW· v4
3.1 LOW· v3
2.1 LOW· v2
A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The...Show more
A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less