Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-266

MITRE ↗

CWE-266

122
CRITICAL
343
HIGH
567
MEDIUM
41
LOW
1,094 CVEs · Page 2/22
9.6
CVE-2026-11861

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Direct

9.4
CVE-2026-32916

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e

9.1
CVE-2026-22908

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially comprom

9.1
CVE-2025-10263

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4

9.1
CVE-2026-10059

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namesp

9.0
CVE-2026-32519

Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affect

8.8
CVE-2025-29004

Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Re

8.8
CVE-2025-31643

Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPC

8.8
CVE-2025-50007

Incorrect Privilege Assignment vulnerability in Jthemes xSmart xsmart allows Privilege Escalation.This issue affects xSm

8.8
CVE-2025-67966

Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.

8.8
CVE-2025-69182

Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege

8.8
CVE-2025-69183

Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Pri

8.8
CVE-2025-69292

Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This i

8.8
CVE-2025-69293

Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue a

8.8
CVE-2026-25414

Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This

8.8
CVE-2026-32530

Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue

8.8
CVE-2026-27668

A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). U

8.8
CVE-2026-6750

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.

8.8
CVE-2026-5141

Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM S

8.8
CVE-2026-45216

Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects

8.8
CVE-2026-35671

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint

8.8
CVE-2025-15656

Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affe

8.8
CVE-2026-45830

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us

8.8
CVE-2026-49111

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affe

8.8
CVE-2026-39579

Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.

8.8
CVE-2026-48889

Subscriber Privilege Escalation in Amelia <= 2.3 versions.

8.8
CVE-2026-49780

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

8.8
CVE-2026-12289

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.

8.8
CVE-2025-59563

Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.

8.8
CVE-2025-69138

Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.

8.8
CVE-2026-54805

Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

8.8
CVE-2026-56008

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

8.8
CVE-2026-56010

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

8.8
CVE-2026-56247

Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compa

8.8
CVE-2026-5136

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call

8.8
CVE-2026-59093

Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted

8.8
CVE-2026-57386

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affec

8.8
CVE-2026-57410

Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.Thi

8.8
CVE-2026-21824

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso

8.8
CVE-2026-59541

Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

8.8
CVE-2026-17626

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitiv

8.8
CVE-2026-28111

Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

8.8
CVE-2026-28161

Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.

8.8
CVE-2026-72840

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/cro

8.8
CVE-2026-72826

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subs

8.8
CVE-2026-28191

Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.

8.8
CVE-2026-32561

Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

8.3
CVE-2026-53814

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly rece

8.2
CVE-2026-57768

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege

8.2
CVE-2026-73350

Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.

Frequently Asked Questions

What is CWE-266?

CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-266?

There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.

How can I protect against CWE-266 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.

Detect CWE-266 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.

Get Started