Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-266'

View all threats tagged with 'cwe-266'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-266

Threats Tagged 'cwe-266'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-18976: Incorrect Privilege Assignment in NousResearch hermes-agentCVE-2026-18976
0

A vulnerability in NousResearch hermes-agent up to version 0.16.0 allows remote attackers to cause incorrect privilege assignment via the get_tool_definitions function in agent/agent_init.py. This issue relates to improper handling in the disabled_toolsets Handler component. The vulnerability has a CVSS score of 6.3 and has been publicly disclosed, but no known exploits are currently observed in the wild.

Join the discussion
CVE-2026-18993: Improper Access Controls in NousResearch hermes-agentCVE-2026-18993
0

A vulnerability exists in NousResearch hermes-agent up to version 0.16.0 in the Memory Toolset component, specifically in the hermes-agent/model_tools.py file. This issue involves improper access controls that can be exploited remotely. The vulnerability has a CVSS 3.1 score of 6.3, indicating a medium severity level. Exploit code for this vulnerability is publicly available, but there are no known exploits observed in the wild. No patch or official fix information is currently provided.

Join the discussion
CVE-2026-18996: Incorrect Privilege Assignment in cosmicstack-labs mercury-agentCVE-2026-18996
0

A vulnerability in cosmicstack-labs mercury-agent up to version 1.1.12 affects the PermissionManager.checkShellCommand function in the run_command Handler component. This flaw leads to incorrect privilege assignment and can be exploited remotely. The vulnerability has a CVSS score of 6.3, indicating a medium severity impact on confidentiality, integrity, and availability. The issue was reported early to the project, but no response or patch has been provided yet. Public exploit details are available, but no known exploitation in the wild has been confirmed.

Join the discussion
CVE-2026-18998: Improper Authorization in cosmicstack-labs mercury-agentCVE-2026-18998
0

A vulnerability exists in cosmicstack-labs mercury-agent up to version 1.1.12 affecting the SubAgent.run function in the delegate_task Tool component. This vulnerability allows improper authorization through a remotely executable manipulation. The issue was reported early to the project, but no response or fix has been provided yet. The vulnerability has a CVSS score of 6.3, indicating a medium severity level. Exploit code has been publicly disclosed, but there are no known exploits in the wild at this time.

Join the discussion
CVE-2026-19007: Improper Privilege Management in mf-yang openclaw-cnCVE-2026-19007
0

A vulnerability in mf-yang openclaw-cn up to version 0.2.1 affects the isApprovedElevatedSender function in the src/auto-reply/reply/reply-elevated.ts file. This vulnerability involves improper privilege management and can be exploited remotely. The issue has been publicly disclosed, but the project has not yet responded or issued a fix.

Join the discussion
CVE-2026-19005: Improper Privilege Management in nanocoai NanoClawCVE-2026-19005
0

A vulnerability in nanocoai NanoClaw up to version 2.0.64 affects the handleCreateAgent function in the Child-Agent Creation component. This flaw involves improper privilege management that can be exploited remotely. The exploit code is publicly available, but there is no vendor response or patch at this time.

Join the discussion
CVE-2025-4374: Incorrect Privilege Assignment in Project Quay quayCVE-2025-4374
0

A vulnerability in Red Hat Quay allows users or robots to gain 'Admin' permissions on newly created repositories when acting as a proxy cache and pulling images that have not yet been mirrored. This issue is tracked as CVE-2025-4374 and has a CVSS 3.1 base score of 6.5, indicating a medium severity. Red Hat has released fixed versions 3.13.6 and 3.14.2 to address this flaw.

Join the discussion
CVE-2026-66662: CWE-266 Incorrect Privilege Assignment in Shabti Kaplan Frontend Admin by DynamiAppsCVE-2026-66662
0

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

Join the discussion
CVE-2026-65559: CWE-266 Incorrect Privilege Assignment in tychesoftwares Order Delivery Date for WooCommerceCVE-2026-65559
0

Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.

Join the discussion
CVE-2026-65507: CWE-266 Incorrect Privilege Assignment in Sergey AIWUCVE-2026-65507
0

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

Join the discussion

Showing 1 to 10 of 23 results

Filters:Tag: cwe-266
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses