# CWE-266: Incorrect Privilege Assignment

**KEV-linked**

> As of 2026-10-05, CWE-266 (Incorrect Privilege Assignment) underlies 19 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 4 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-266?

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

CWE-266 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/266.html) (CWE-266 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control** — Gain Privileges or Assume Identity. A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

_Source: MITRE CWE, common consequences._

## How CWE-266 is exploited in the wild

Threadlinqs maps 19 CVEs to CWE-266, published between 2024-08-21 and 2026-09-27. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 3 critical, 2 high, 11 medium, 1 low. The highest EPSS score in the set is 68.2% (CVE-2024-28000), the modelled probability of exploitation in the next 30 days. 4 tracked threats reference CWE-266 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)” (2026-09-13). Affected products concentrate in FreeBSD (2), nanocoai (2), CodeAstro (1), among 13 vendors in total.

## Vulnerabilities (CVEs)

All 19 CVEs mapped to CWE-266, CISA KEV first, then by CVSS score.

- [CVE-2026-48172](https://intel.threadlinqs.com/cve/CVE-2026-48172) — CISA KEV · CVSS 9.8 critical · EPSS 7.9% · published 2026-05-21
- [CVE-2024-28000](https://intel.threadlinqs.com/cve/CVE-2024-28000) — CVSS 9.8 critical · EPSS 68.2% · published 2024-08-21
- [CVE-2026-78267](https://intel.threadlinqs.com/cve/CVE-2026-78267) — CVSS 9.8 critical · published 2026-08-24
- [CVE-2026-86583](https://intel.threadlinqs.com/cve/CVE-2026-86583) — CVSS 8.8 high · EPSS 0.3% · published 2026-09-23
- [CVE-2026-94425](https://intel.threadlinqs.com/cve/CVE-2026-94425) — CVSS 8.8 high · EPSS 0.1% · published 2026-09-21
- [CVE-2026-94048](https://intel.threadlinqs.com/cve/CVE-2026-94048) — CVSS 6.6 medium · EPSS 0.2% · published 2026-09-20
- [CVE-2026-94047](https://intel.threadlinqs.com/cve/CVE-2026-94047) — CVSS 6.3 medium · EPSS 0.4% · published 2026-09-20
- [CVE-2026-15509](https://intel.threadlinqs.com/cve/CVE-2026-15509) — CVSS 6.3 medium · EPSS 0.3% · published 2026-07-12
- [CVE-2026-15510](https://intel.threadlinqs.com/cve/CVE-2026-15510) — CVSS 6.3 medium · EPSS 0.3% · published 2026-07-12
- [CVE-2026-16764](https://intel.threadlinqs.com/cve/CVE-2026-16764) — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-23
- [CVE-2026-17434](https://intel.threadlinqs.com/cve/CVE-2026-17434) — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-26
- [CVE-2026-100883](https://intel.threadlinqs.com/cve/CVE-2026-100883) — CVSS 6.3 medium · published 2026-09-27
- [CVE-2026-17433](https://intel.threadlinqs.com/cve/CVE-2026-17433) — CVSS 5.3 medium · EPSS 0.1% · published 2026-07-26
- [CVE-2026-17432](https://intel.threadlinqs.com/cve/CVE-2026-17432) — CVSS 5 medium · EPSS 0.2% · published 2026-07-26
- [CVE-2026-86228](https://intel.threadlinqs.com/cve/CVE-2026-86228) — CVSS 4.3 medium · EPSS 0.2% · published 2026-09-06
- [CVE-2026-90487](https://intel.threadlinqs.com/cve/CVE-2026-90487) — CVSS 4.3 medium · published 2026-09-12
- [CVE-2026-13511](https://intel.threadlinqs.com/cve/CVE-2026-13511) — CVSS 3.1 low · EPSS 0.2% · published 2026-06-28
- [CVE-2026-49413](https://intel.threadlinqs.com/cve/CVE-2026-49413) — EPSS 0.1% · published 2026-06-27
- [CVE-2026-45259](https://intel.threadlinqs.com/cve/CVE-2026-45259) — EPSS 0.1% · published 2026-06-27

## Affected vendors

- [FreeBSD](https://intel.threadlinqs.com/vendors/freebsd) — 2 CVEs
- **nanocoai** — 2 CVEs
- **CodeAstro** — 1 CVE
- **Cozmoslabs** — 1 CVE
- **Krayin** — 1 CVE
- **LiteSpeed Technologies** — 1 CVE
- **Litespeedtech** — 1 CVE
- **Moore Threads** — 1 CVE
- **NousResearch** — 1 CVE
- **OWASP** — 1 CVE
- **Xuxueli** — 1 CVE
- **carazo** — 1 CVE

## Threat activity

4 tracked threats cite CWE-266:

- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL · 2026-09-13
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data](https://intel.threadlinqs.com/threat/TL-2026-2172) — CRITICAL · 2026-08-27
- [Critical Gemini CLI Vulnerability (CVE-2026-12537) Enables Remote Code Execution via Malicious .env Workspace Trust Bypass](https://intel.threadlinqs.com/threat/TL-2026-1206) — CRITICAL · 2026-07-11
- [LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-0565) — CRITICAL · 2026-05-22

## Mitigations

- **Architecture and Design, Operation**: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- **Architecture and Design, Operation / Environment Hardening**: Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.

_Source: MITRE CWE, potential mitigations._

## Related weaknesses

- [CWE-269 Improper Privilege Management](https://intel.threadlinqs.com/cwe/CWE-269)
- [CWE-286](https://cwe.mitre.org/data/definitions/286.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-266
Source definition: https://cwe.mitre.org/data/definitions/266.html
Detection rules and IOCs for threats exploiting CWE-266 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
