CWE-266: CWE-266
Yearly Trend
Top Affected Vendors
All CWE-266 CVEs (417)
CVE-2025-14889 is an authorization bypass vulnerability in Campcodes Advanced Voting Management System 1.0 that allows attackers to manipulate voter r...
Dec 18, 2025This vulnerability in Ningyuanda TC155 57.0.2.0 allows attackers on the local network to perform unauthorized factory resets via the ONVIF Device Mana...
Dec 16, 2025This vulnerability in macrozheng mall-swarm allows unauthorized deletion of user read history records through improper authorization in the delete fun...
Dec 4, 2025This vulnerability in ZenTao's file handler allows attackers to manipulate file deletion operations through improper privilege management. Attackers c...
Nov 30, 2025This vulnerability in macrozheng mall allows attackers to bypass access controls and delete user read history records without proper authorization. Re...
Nov 20, 2025This vulnerability allows attackers to cancel orders without proper authorization in macrozheng mall-swarm and mall applications. Attackers can exploi...
Nov 13, 2025This vulnerability allows improper authorization in macrozheng mall-swarm and mall applications up to version 1.0.3. Attackers can manipulate the orde...
Nov 13, 2025This vulnerability in SeriaWei ZKEACMS allows unauthorized deletion of URL redirection entries through improper authorization in the POST request hand...
Oct 4, 2025This CVE describes a privilege escalation vulnerability in NetApp StorageGRID where authenticated attackers can discover Grid node names and IP addres...
Sep 19, 2025CRMEB versions up to 5.6.1 contain an improper authorization vulnerability in the editAddress function that allows attackers to manipulate address IDs...
Sep 14, 2025This vulnerability in CRMEB allows attackers to manipulate administrator password reset functionality to gain unauthorized access. It affects CRMEB in...
Sep 14, 2025CVE-2025-9937 is an improper authorization vulnerability in elunez eladmin's LocalStorageController deleteFile function that allows unauthorized file ...
Sep 4, 2025This vulnerability in SAP NetWeaver Application Server for ABAP allows authenticated users to bypass authorization controls in the barcode interface, ...
Aug 12, 2025CVE-2025-7947 is an improper authorization vulnerability in jshERP's account deletion function that allows attackers to delete user accounts without p...
Jul 22, 2025This vulnerability allows remote attackers to delete chat histories they shouldn't have access to due to improper access controls in the deleteChat fu...
Mar 15, 2025This vulnerability in StarSea99 starsea-mall allows attackers to bypass access controls and modify user information by manipulating the userId paramet...
Mar 7, 2025This vulnerability allows remote authenticated users to escalate their privileges in Hitachi Storage Plug-in for VMware vCenter. Attackers with existi...
Oct 6, 2022This vulnerability in TIM BPM Suite & TIM FLOW allows remote attackers to escalate privileges by exploiting weak MD5 password hashes stored by the app...
Jan 9, 2026This vulnerability in roncoo-pay allows improper authorization through manipulation of the /user/info/lookupList endpoint, potentially enabling unauth...
Sep 26, 2025This critical vulnerability in SourceCodester Student Result Management System 1.0 allows unauthorized privileged user creation through improper acces...
Jun 5, 2025CVE-2025-5175 is an improper authorization vulnerability in erdogant pypickle's Save function that allows local attackers to bypass intended access co...
May 26, 2025This vulnerability in Weitong Mall 1.0.0 allows remote attackers to bypass access controls by manipulating the 'isDelete' parameter in the /historyLis...
Apr 30, 2025CVE-2025-4064 is an improper access control vulnerability in ScriptAndTools Online-Travling-System 1.0 that allows unauthorized access to the admin vi...
Apr 29, 2025This critical vulnerability in baseweb JSite 1.0's Apache Druid Monitoring Console allows unauthorized access to the /druid/index.html component due t...
Apr 18, 2025This critical vulnerability in TOTOLINK A3700R routers allows attackers to bypass access controls on the setL2tpServerCfg function via the /cgi-bin/cs...
Apr 16, 2025This vulnerability allows remote attackers to bypass access controls on TOTOLINK A3700R routers via the setScheduleCfg function in the web interface. ...
Apr 16, 2025This critical vulnerability in TOTOLINK A3700R routers allows attackers to bypass access controls on the setWiFiEasyGuestCfg function via the /cgi-bin...
Apr 16, 2025This vulnerability in Tenda FH1202 routers allows attackers to bypass access controls via the /goform/wrlwpsset endpoint, potentially enabling unautho...
Apr 4, 2025This vulnerability in Tenda FH1202 routers allows attackers to bypass access controls on the web management interface's SysToolDDNS component. Attacke...
Mar 31, 2025This critical vulnerability in Tenda FH1202 routers allows improper access controls through manipulation of the /default.cfg file, potentially enablin...
Mar 31, 2025This critical vulnerability in Tenda FH1202 routers allows remote attackers to bypass access controls via the web management interface. Attackers can ...
Mar 31, 2025This critical vulnerability in Tenda FH1202 routers allows attackers to bypass access controls via the /goform/AdvSetWrlGstset endpoint in the web man...
Mar 31, 2025This vulnerability allows remote attackers to improperly access the IBMS configuration file handler in TOTOLINK A3000RU routers. Attackers can exploit...
Mar 30, 2025This critical vulnerability in ywoa allows remote attackers to bypass authorization controls via the /oa/setup/setup.jsp file. It affects all ywoa ins...
Feb 12, 2025This vulnerability in AlDente Charge Limiter allows local attackers to bypass authorization checks in the XPC service, potentially enabling unauthoriz...
Feb 6, 2025This vulnerability in MicroWorld eScan Antivirus 7.0.32 on Linux allows local attackers to exploit incorrect default permissions in the installation h...
Jan 8, 2025CVE-2025-0206 is a critical improper access control vulnerability in code-projects Online Shoe Store 1.0 that allows unauthorized access to the admin ...
Jan 4, 2025This vulnerability allows unauthorized access to the /doc.html endpoint in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2...
Jan 2, 2025This vulnerability in D-Link DIR-816 routers allows unauthorized access to the IP QoS configuration handler due to improper access controls. Attackers...
Jan 2, 2025This vulnerability allows remote attackers to bypass authentication and access WiFi settings on affected D-Link DIR-816 A2 routers. Attackers can modi...
Jan 2, 2025CVE-2024-13067 is an improper access control vulnerability in CodeAstro Online Food Ordering System 1.0 that allows unauthorized access to the admin/a...
Dec 31, 2024This vulnerability in FoxCMS allows attackers to bypass authorization controls by manipulating password parameters in the API endpoint. It affects all...
Dec 23, 2024This CVE describes an improper authorization vulnerability in the Druid monitoring interface of Jeewms warehouse management software. Attackers can re...
Dec 9, 2024This vulnerability allows authenticated users in IBM Jazz Foundation to modify dashboards they shouldn't have access to by sending specially crafted H...
Nov 25, 2024This critical vulnerability in Altenergy Power Control Software allows unauthorized access to database information through improper authorization on t...
Nov 18, 2024This vulnerability allows remote attackers to bypass authentication on TOTOLINK LR350 routers by manipulating the authCode parameter in the /formLogin...
Nov 1, 2024An incorrect privilege assignment vulnerability in OTRS allows agents with read-only permissions to gain full access to tickets in rare configurations...
Jul 15, 2024This vulnerability in Aquarius HelperTool (1.0.003) on macOS allows local attackers to escalate privileges to root. The XPC service fails to validate ...
Dec 3, 2025This macOS vulnerability allows malicious applications to hijack entitlements granted to other privileged apps, potentially gaining unauthorized acces...
Jul 30, 2025This CVE describes an improper authorization vulnerability in WeKan's REST API that allows attackers to manipulate board organization settings through...
Feb 4, 2026About CWE-266 (CWE-266)
Our database tracks 417 CVEs classified as CWE-266, with 48 rated critical and 131 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.
External reference: View CWE-266 on MITRE CWE →
Monitor CWE-266 Vulnerabilities
Get alerted when new CWE-266 CVEs affect your infrastructure.
Start Monitoring Free