Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local
A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.9.0), RUGGEDCOM RMC8388NC V5.X (All ver
Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/
Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low pri
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requ
A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af
Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace thr
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiat
A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools
NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged op
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this iss
A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attacke
A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects a
A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerab
A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access.
A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulner
A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affect
A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared a
Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Applianc
eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allo
Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to byp
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an adminis
An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerab
A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. Th
IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This
A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown funct
A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects so
An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escala
An issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges via the Session Expirat
A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an un
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects
A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This aff
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interfa
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows
IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.
A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to re
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected r
The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to
The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to in
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via serv
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started