A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Volume of CVEs assigned to CWE-266 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,006 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48172CRITICAL LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of gre | May 21, 2026 | 9.8 | 88 | YES | NO |
CVE-2024-28000CRITICAL Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 6.3.0.1. | Aug 21, 2024 | 9.8 | 84 | NO | YES |
CVE-2025-27007CRITICAL Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82. | May 1, 2025 | 9.8 | 83 | NO | YES |
CVE-2026-23550CRITICAL Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1. | Jan 14, 2026 | 9.8 | 61 | NO | YES |
CVE-2025-47539CRITICAL Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26. | May 23, 2025 | 9.8 | 57 | NO | YES |
CVE-2025-41115CRITICAL SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifec | Nov 21, 2025 | 9.8 | 45 | NO | NO |
CVE-2022-20759HIGH A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software c | May 3, 2022 | 8.8 | 44 | NO | NO |
CVE-2026-57813CRITICAL Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3. | Jul 13, 2026 | 9.8 | 42 | NO | NO |
CVE-2025-10263CRITICAL Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex | Jun 9, 2026 | 9.1 | 42 | NO | NO |
CVE-2025-34112CRITICAL An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability | Jul 15, 2025 | 10.0 | 42 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.