The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez L
Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez:
Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue af
Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privil
Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege E
Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation.
Incorrect Privilege Assignment vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows
Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege E
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/defau
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the
eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a us
Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtainin
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose app
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege
Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be ac
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Conve
Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated
Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to
In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the De
Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who
In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRea
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir
A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several ro
A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected i
A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on
A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on
Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specif
In the Linux kernel, the following vulnerability has been resolved: ethtool: strset: fix message length calculation Ou
The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and region
IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations du
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically define
LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attack
A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory
A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-m
IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority req
A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 an
A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the fu
The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to,
The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or
Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high p
A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications acc
Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of
An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting
A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high p
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started