Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-266 (特权授予不正确) — Vulnerability Class 477

477 vulnerabilities classified as CWE-266 (特权授予不正确). AI Chinese analysis included.

CWE-266 represents a critical access control weakness where software incorrectly assigns privileges to an actor, granting them an unintended sphere of control. This flaw typically arises from flawed logic in role-based or discretionary access control mechanisms, allowing users to perform actions beyond their authorized scope. Attackers exploit this by manipulating input parameters or session tokens to escalate privileges, effectively bypassing security boundaries to access sensitive data or execute administrative functions. To prevent such vulnerabilities, developers must implement robust, centralized authorization checks that verify permissions at every critical point of execution rather than relying on client-side validations. Adhering to the principle of least privilege ensures that actors receive only the minimum access necessary for their specific tasks. Rigorous code reviews and automated security testing further help identify incorrect privilege assignments before deployment, maintaining strict integrity over system resources.

MITRE CWE Description
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Common Consequences (1)
Access ControlGain Privileges or Assume Identity
A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.
Mitigations (2)
Architecture and Design, OperationVery carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
Architecture and Design, OperationRun your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database ad…
Examples (2)
The following example demonstrates the weakness.
seteuid(0); /* do some stuff */ seteuid(getuid());
Bad · C
The following example demonstrates the weakness.
AccessController.doPrivileged(new PrivilegedAction() { public Object run() { // privileged code goes here, for example: System.loadLibrary("awt"); return null; // nothing to return }
Bad · Java
CVE IDTitleCVSSSeverityPublished
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey — grav 9.8 Critical2026-08-14
CVE-2026-72840 OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write — luci 8.8 High2026-08-13
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup — filebrowser 9.8 Critical2026-08-13
CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation — Gitea Open Source Git Server--2026-08-13
CVE-2026-66661 WordPress Directories Pro plugin <= 2.0.5 - Privilege Escalation vulnerability — Directories Pro 7.7 High2026-08-13
CVE-2026-66424 WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability — SMS Alert Order Notifications 9.8 Critical2026-08-13
CVE-2026-61979 WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerability — SAML SP Single Sign On 8.1 High2026-08-13
CVE-2026-28161 WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerability — Service Finder Booking 8.8 High2026-08-13
CVE-2026-27543 WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability — MStore API 8.1 High2026-08-13
CVE-2025-9486 Incorrect Privilege Assignment in GitLab — GitLab 3.3 Low2026-08-12
CVE-2026-64639 WebPros Plesk 权限许可和访问控制问题漏洞 — Plesk 9.3 Critical2026-08-12
CVE-2026-71468 Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache — Red Hat Advanced Cluster Management for Kubernetes 2 5.3 Medium2026-08-11
CVE-2026-18621 Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening — Red Hat OpenShift AI 2.25 7.6 High2026-08-10
CVE-2026-15467 Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass protected environment variable filtering, allowing trust_remote_code policy override — Red Hat OpenShift AI 2.25 8.1 High2026-08-10
CVE-2026-66662 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability — Frontend Admin by DynamiApps 9.8 Critical2026-08-06
CVE-2026-65559 WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability — Order Delivery Date for WooCommerce 7.2 High2026-08-06
CVE-2026-65507 WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability — AIWU 9.8 Critical2026-08-06
CVE-2026-28111 WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability — Forminator 8.8 High2026-08-06
CVE-2026-18996 cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.checkShellCommand privileges assignment — mercury-agent 6.3 Medium2026-08-06
CVE-2026-18976 NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment — hermes-agent 6.3 Medium2026-08-06
CVE-2026-17626 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS 8.8 High2026-08-05
CVE-2026-20028 Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability — Cisco Terminal Services Agent 5.0 Medium2026-08-05
CVE-2026-10059 Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token — Multicluster Engine for Kubernetes 9.1 Critical2026-08-05
CVE-2026-52791 fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC) — fuse-overlayfs 2.0 Low2026-07-29
CVE-2026-61951 WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability — TrueBooker 9.8 Critical2026-07-23
CVE-2026-59541 WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability — WP BASE Booking 8.8 High2026-07-23
CVE-2026-59540 WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability — SMS Alert Order Notifications 9.8 Critical2026-07-23
CVE-2026-47237 Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Authorization Token Stealing — community-distribution 8.0 High2026-07-21
CVE-2026-21824 A privilege escalation vulnerability affects HCL Commerce — Commerce 8.8 High2026-07-20
CVE-2026-50562 FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows — FastGPT--2026-07-15

Vulnerabilities classified as CWE-266 (特权授予不正确) represent 477 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.