CWE-266: CWE-266
Yearly Trend
Top Affected Vendors
All CWE-266 CVEs (417)
This vulnerability in Red Hat OpenShift AI Service's TrustyAI component grants excessive permissions to all authenticated users and service accounts. ...
Oct 28, 2025This vulnerability in Frappe LMS 2.35.0 allows attackers to bypass access controls on unpublished courses through the /courses/ endpoint. Attackers ca...
Oct 5, 2025This vulnerability in ClassCMS allows attackers to perform vertical privilege escalation through improper privilege handling in the user management co...
Dec 16, 2024This vulnerability allows unauthorized access to system dashboard information in CoCoTeaNet CyreneAdmin up to version 1.3.0. Attackers can remotely ex...
Feb 19, 2026This vulnerability in WeKan allows improper access controls through the REST endpoint, potentially enabling unauthorized access to board data. It affe...
Feb 5, 2026This CVE describes an improper authorization vulnerability in Zhong Bang CRMEB's store integration API endpoint. Attackers can manipulate the order_id...
Feb 1, 2026This vulnerability allows attackers with limited permissions to write files to specific locations on affected devices, potentially enabling system man...
Jan 15, 2026This vulnerability allows low-privileged attackers to trigger critical system functions like reboot or factory reset without proper authorization. It ...
Jan 15, 2026This vulnerability in Student File Management System 1.0 allows attackers to bypass authorization controls when downloading files via the /download.ph...
Dec 30, 2025This vulnerability allows unauthorized modification of member address data in macrozheng mall versions up to 1.0.3. Attackers can exploit improper aut...
Dec 28, 2025This vulnerability allows improper authorization in the submitOrderPayment function of youlai-mall, potentially enabling unauthorized order manipulati...
Dec 25, 2025This vulnerability in youlaitech youlai-mall allows improper access controls via the getMemberByMobile function, enabling unauthorized access to membe...
Dec 25, 2025This vulnerability allows unauthorized users to manipulate the balance deduction function in youlai-mall e-commerce platform, potentially enabling una...
Dec 25, 2025This CVE describes an improper authorization vulnerability in orionsec orion-ops API that allows unauthorized access to machine key functionality. Att...
Dec 1, 2025This vulnerability allows unauthorized access to order details in macrozheng mall-swarm and mall applications. Attackers can manipulate the orderId pa...
Nov 13, 2025This vulnerability allows attackers to bypass authorization checks in the TIME-SEA-PLUS software's order status handler. Remote attackers can exploit ...
Oct 27, 2025This vulnerability in JhumanJ OpnForm up to version 1.9.3 allows improper access controls via the /edit endpoint, potentially enabling unauthorized ac...
Oct 8, 2025This CVE describes an improper authorization vulnerability in the wisdom-education software up to version 1.0.4. Attackers can remotely manipulate the...
Sep 27, 2025This vulnerability in JeecgBoot allows unauthorized access to the tenant export function via the /sys/tenant/exportXls endpoint. Attackers can remotel...
Sep 26, 2025JeecgBoot up to version 3.8.2 contains an improper authorization vulnerability in the /sys/position/exportXls endpoint that allows remote attackers to...
Sep 26, 2025This vulnerability in JeecgBoot allows unauthorized access to the user export functionality via the /sys/user/exportXls endpoint. Attackers can exploi...
Sep 25, 2025JeecgBoot up to version 3.8.2 has an improper authorization vulnerability in the /sys/role/exportXls endpoint that allows unauthorized access to role ...
Sep 25, 2025CVE-2025-10822 is an improper authorization vulnerability in the fuyang_lipengjun platform 1.0 that allows unauthorized access to SMS log data via the...
Sep 23, 2025This vulnerability allows unauthorized access to topic category data in fuyang_lipengjun platform 1.0 due to improper authorization in the TopicCatego...
Sep 22, 2025This vulnerability in the fuyang_lipengjun platform 1.0 allows unauthorized access to the TopicController's queryAll function, enabling attackers to r...
Sep 22, 2025This vulnerability in fuyang_lipengjun platform 1.0 allows unauthorized access to user coupon data through the UserCouponController queryAll function....
Sep 22, 2025This vulnerability in fuyang_lipengjun platform 1.0 allows improper authorization through the BrandController function at /brand/queryAll. Attackers c...
Sep 18, 2025CVE-2025-10674 is an improper authorization vulnerability in the fuyang_lipengjun platform 1.0 that allows attackers to access the /attributecategory/...
Sep 18, 2025This vulnerability in fuyang_lipengjun platform 1.0 allows improper authorization via the AttributeController function at /attribute/queryAll, enablin...
Sep 18, 2025This vulnerability in newbee-mall's order status handler allows attackers to manipulate order numbers to bypass authorization checks. Remote attackers...
Sep 15, 2025This vulnerability allows unauthorized access to error log details in elunez eladmin systems. Attackers can remotely exploit improper authorization in...
Sep 8, 2025This vulnerability in Portabilis i-Educar allows unauthorized access to class information through the /module/Api/turma endpoint. Attackers can exploi...
Sep 8, 2025This vulnerability allows attackers to bypass intended access controls in the Site Offline WordPress plugin, potentially accessing restricted function...
Aug 28, 2025This vulnerability in Portabilis i-Educar allows attackers to bypass authorization controls by manipulating the ID parameter in the /module/Api/pessoa...
Aug 10, 2025This is a mass assignment vulnerability in Litemall 1.8.0 that allows unauthorized manipulation of adminComment parameters. Attackers can exploit this...
Jun 26, 2025This vulnerability allows unauthenticated access to live video streams and recorded video files from SIFUSM/MZZYG BD S1 dashcams. Attackers on the sam...
Jun 24, 2025This vulnerability allows unauthorized configuration changes on 70mai 1S dashcams via a local network attack. Attackers on the same network can modify...
Jun 23, 2025This vulnerability in Novel-Plus allows unauthorized access to log viewing functionality due to improper authorization in the LogController. Attackers...
Apr 28, 2025CVE-2025-3977 is an improper authorization vulnerability in iteachyou Dreamer CMS that allows attackers to bypass access controls on the attachment do...
Apr 27, 2025This vulnerability allows unauthorized access to the Teacher String Handler component in huanfenz/code-projects StudentManager, potentially enabling a...
Apr 14, 2025CVE-2025-3305 is an improper access control vulnerability in IKUN_Library 1.0 that allows remote attackers to bypass authorization checks in the Borro...
Apr 5, 2025This vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to bypass access controls through manipulation of the email parameter in...
Apr 5, 2025This vulnerability allows attackers with low-privileged JumpServer accounts to manipulate Kubernetes session configurations to redirect API requests t...
Mar 31, 2025This vulnerability in TOTOLINK A3000RU routers allows improper access to the Syslog configuration file handler via /cgi-bin/ExportSyslog.sh. Attackers...
Mar 24, 2025This vulnerability in JIZHICMS allows improper authorization through manipulation of the 'ishot' parameter in the Article Handler component. Attackers...
Mar 23, 2025This vulnerability in D-Link DIR-618 and DIR-605L routers allows improper access control to the /goform/formVirtualServ endpoint, potentially enabling...
Mar 20, 2025This vulnerability in D-Link DIR-618 and DIR-605L routers allows attackers with local network access to bypass access controls via the /goform/formSet...
Mar 20, 2025This CVE describes an improper access control vulnerability in D-Link DIR-618 and DIR-605L routers affecting the /goform/formSetPassword endpoint. Att...
Mar 20, 2025This vulnerability allows unauthorized access to video footage and live video streams in i-Drive i11 and i12 devices due to improper access controls. ...
Mar 3, 2025TeamPass versions before 3.1.3.1 contain an authorization bypass vulnerability where users can access folder information without proper permission che...
Dec 30, 2024About CWE-266 (CWE-266)
Our database tracks 417 CVEs classified as CWE-266, with 48 rated critical and 131 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.
External reference: View CWE-266 on MITRE CWE →
Monitor CWE-266 Vulnerabilities
Get alerted when new CWE-266 CVEs affect your infrastructure.
Start Monitoring Free