IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privi
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited
In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confuse
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the back
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditio
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. T
HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access rega
Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plug
Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the worksp
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions star
A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespac
HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates u
The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-admini
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA)
A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst
A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Fami
A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all us
The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Syste
A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by t
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affect
A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified as critical. This issue
A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects some unknown processing o
A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /in
A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of
A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the fun
A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown
A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown func
A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown f
This issue was addressed by removing additional entitlements. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchO
Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authent
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as cr
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic.
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected i
A vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file
A vulnerability, which was classified as problematic, has been found in Dot Tech Smart Campus System. Affected by this i
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Br
A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execut
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-me
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as ship
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started