A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Direct
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e
Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially comprom
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namesp
Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affect
Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Re
Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPC
Incorrect Privilege Assignment vulnerability in Jthemes xSmart xsmart allows Privilege Escalation.This issue affects xSm
Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.
Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege
Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Pri
Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This i
Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue a
Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This
Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). U
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM S
Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects
phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint
Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affe
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us
Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affe
Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
Customer Privilege Escalation in Dokan <= 5.0.2 versions.
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.
Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.
Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.
Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compa
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call
Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted
Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affec
Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.Thi
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitiv
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/cro
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subs
Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly rece
Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started