CWE-266: CWE-266

418
Total CVEs
48
Critical
131
High
6.7
Avg CVSS

Yearly Trend

2026
75
2025
267
2024
59
2023
5
2022
4

Top Affected Vendors

1 Jeecg 11
2 Portabilis 11
3 Dell 10
4 Google 9
5 Fuyang Lipengjun 8
6 Macrozheng 8
7 Dlink 8
8 Totolink 7
9 Wekan Project 7
10 Youlai 6

All CWE-266 CVEs (418)

CVE-2024-50701
4.3

TeamPass versions before 3.1.3.1 contain an authorization bypass vulnerability where users can access folder information without proper permission che...

Dec 30, 2024
CVE-2024-11073
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in SourceCodester Hospital Management System 1.0. Attackers can remotely d...

Nov 11, 2024
CVE-2026-2010
4.2

This CVE describes an improper authorization vulnerability in Sanluan PublicCMS's trade payment handler. Attackers can manipulate payment IDs to bypas...

Feb 6, 2026
CVE-2024-57967
4.2

This vulnerability in CyberArk's Password Vault Web Access (PVWA) allows potential privilege escalation through LDAP mapping misconfiguration. It affe...

Feb 3, 2025
CVE-2024-10978
4.2

This PostgreSQL vulnerability allows a less-privileged application user to view or modify unintended database rows when the application uses SET ROLE ...

Nov 14, 2024
CVE-2024-49731
4.0

This vulnerability allows telemetry opt-in settings corruption on other Pixel Watches when setting up a new watch, potentially enabling local privileg...

Sep 4, 2025
CVE-2025-48526
4.0

This vulnerability allows an Android app to launch the ChooserActivity in another user profile without proper authorization due to improper input vali...

Sep 4, 2025
CVE-2025-48528
4.0

This CVE describes a tapjacking/overlay vulnerability in Android's biometric authentication system that allows attackers to overlay legitimate biometr...

Sep 4, 2025
CVE-2025-26425
4.0

This CVE describes a permission squatting vulnerability in Android's RoleService that allows local privilege escalation on affected versions. It affec...

Sep 4, 2025
CVE-2025-15126
3.1

This CVE describes an improper authorization vulnerability in JeecgBoot's getPositionUserList function. Attackers can manipulate the positionId parame...

Dec 28, 2025
CVE-2025-15124
3.1

This vulnerability in JeecgBoot allows attackers to bypass authorization checks by manipulating the departId parameter in the /sys/sysDepartPermission...

Dec 28, 2025
CVE-2025-15125
3.1

This CVE describes an improper authorization vulnerability in JeecgBoot's queryDepartPermission function. Attackers can manipulate the departId parame...

Dec 28, 2025
CVE-2025-15123
3.1

JeecgBoot up to version 3.9.0 contains an improper authorization vulnerability in the /sys/sysDepartPermission/datarule/ endpoint. This allows remote ...

Dec 28, 2025
CVE-2025-15122
3.1

This CVE describes an improper authorization vulnerability in JeecgBoot's loadDatarule function that allows attackers to manipulate departId/roleId pa...

Dec 28, 2025
CVE-2025-15120
3.1

This CVE describes an improper authorization vulnerability in JeecgBoot's getDeptRoleList function. Attackers can manipulate the departId parameter to...

Dec 28, 2025
CVE-2025-15119
3.1

This vulnerability in JeecgBoot allows attackers to bypass authorization checks by manipulating the deptId parameter in the /sys/sysDepartRole/list en...

Dec 28, 2025
CVE-2025-15084
3.1

This vulnerability in youlaitech youlai-mall allows attackers to bypass access controls in the order payment function, potentially manipulating paymen...

Dec 25, 2025
CVE-2025-13881
2.7

This vulnerability allows Keycloak administrators with limited privileges to access sensitive custom user attributes that should be hidden by User Pro...

Feb 2, 2026

About CWE-266 (CWE-266)

Our database tracks 418 CVEs classified as CWE-266, with 48 rated critical and 131 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.

External reference: View CWE-266 on MITRE CWE →

Monitor CWE-266 Vulnerabilities

Get alerted when new CWE-266 CVEs affect your infrastructure.

Start Monitoring Free