CWE-266Base1 in KEV

Incorrect Privilege Assignment

Draft in the CWE catalog · 1,056 CVEs mapped

1,056
CVEs mapped
1
In KEV
6.7
Median CVSS
What it is

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Recent examples
4.3cvss
CVE-2026-86228

JeecgBoot AiragModelController.java exportXls access control

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component.

MEDIUMno explanation yet
epss
4.3cvss
CVE-2026-86212

Open5GS AMF/MME improper authorization

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.

MEDIUMno explanation yet
epss
9.1cvss
CVE-2026-86153

Tenda CP3 Redirect.cpp SetRedirectEnable privileges management

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

CRITICALno explanation yet
epss
The record
Technical detail
CWE ID
CWE-266
Abstraction
Base
Structure
Simple
Status
Draft
References (1)