Threadlinqs IntelligenceStart free

Weakness · BaseCWE-266

CWE-266: Incorrect Privilege Assignment

KEV-linkedBase

As of 2026-10-05, CWE-266 (Incorrect Privilege Assignment) underlies 19 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 4 tracked threats.

CVEs
19Mapped to CWE-266
CISA KEV
1Exploited in the wild
Critical
3CVSS v3 critical CVEs
Threats
4Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-266?

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

CWE-266 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific.

Source: MITRE CWE (CWE-266 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control — Gain Privileges or Assume Identity. A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Source: MITRE CWE, common consequences.

How CWE-266 is exploited in the wild

Threadlinqs maps 19 CVEs to CWE-266, published between 2024-08-21 and 2026-09-27. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 3 critical, 2 high, 11 medium, 1 low. The highest EPSS score in the set is 68.2% (CVE-2024-28000), the modelled probability of exploitation in the next 30 days. 4 tracked threats reference CWE-266 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)” (2026-09-13). Affected products concentrate in FreeBSD (2), nanocoai (2), CodeAstro (1), among 13 vendors in total.

Vulnerabilities (CVEs)

All 19 CVEs mapped to CWE-266, CISA KEV first, then by CVSS score.

Affected vendors

  • FreeBSD — 2 CVEs
  • nanocoai — 2 CVEs
  • CodeAstro — 1 CVE
  • Cozmoslabs — 1 CVE
  • Krayin — 1 CVE
  • LiteSpeed Technologies — 1 CVE
  • Litespeedtech — 1 CVE
  • Moore Threads — 1 CVE
  • NousResearch — 1 CVE
  • OWASP — 1 CVE
  • Xuxueli — 1 CVE
  • carazo — 1 CVE

Threat activity

4 tracked threats cite CWE-266:

Mitigations

  • Architecture and Design, Operation: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
  • Architecture and Design, Operation / Environment Hardening: Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.

Source: MITRE CWE, potential mitigations.