OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to
A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unkno
A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnera
A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragMod
A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToO
A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the fi
A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transa
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file
A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the f
A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/v
A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of
A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function get
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_vi
A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData
A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /ca
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown fun
A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functiona
A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the f
A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the fil
A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin
A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function P
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file
OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to
A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality
A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg
A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file
A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the l
A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalan
A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the compon
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2
A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the
A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversa
A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of th
A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf
A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve s
A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut
Incorrect privilege assignment vulnerability in HYPR Server allows Privilege Escalation.This issue affects HYPR Server:
Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a use
Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, ar
fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branc
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (cu
SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage us
SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated Sna
Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalati
A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for
Frequently Asked Questions
What is CWE-266?
CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-266?
There are 1,098 CVE records associated with CWE-266 in our database. Of these, 122 are critical severity, 343 are high severity, and 567 are medium severity.
How can I protect against CWE-266 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.
Detect CWE-266 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.
Get Started