CWE-250— Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.— MITRE CWE catalog
384 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-250page 1 of 8
- CVE-2024-38813CRITICALCVSS 7.5EG 9.0⚠ KEV2024-09-17
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
- CVE-2025-40602CRITICALCVSS 6.6EG 9.0⚠ KEV2025-12-18
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
- CVE-2026-77521CRITICALCVSS 10.0EG 10.02026-09-21
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execu…
- CVE-2026-4606CRITICALCVSS 10.0EG 10.02026-03-23
GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system. During installation, ERM creates a Windows service that ru…
- CVE-2022-2634CRITICALCVSS 10.0EG 10.02022-08-10
An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploading python files which can be later executed.
- CVE-2022-1517CRITICALCVSS 10.0EG 10.02022-06-24
LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on …
- CVE-2023-4662CRITICALCVSS 9.8EG 10.02023-09-15
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: before 9.
- CVE-2026-70496CRITICALCVSS 9.9EG 9.92026-08-19
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate…
- CVE-2026-72508CRITICALCVSS 9.9EG 9.92026-08-12
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Reso…
- CVE-2026-48584CRITICALCVSS 9.9EG 9.92026-06-19
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50566CRITICALCVSS 9.9EG 9.92026-06-10
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privile…
- CVE-2026-44477CRITICALCVSS 9.9EG 9.92026-05-28
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local …
- CVE-2026-25212CRITICALCVSS 9.9EG 9.92026-04-02
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and …
- CVE-2025-32445CRITICALCVSS 9.9EG 9.92025-04-15
Argo Events is an event-driven workflow automation framework for Kubernetes. A user with permission to create/modify EventSource and Sensor custom resources can gain privileged access to the host system and cluster, even without having dir…
- CVE-2024-8767CRITICALCVSS 9.9EG 9.92024-09-17
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before bu…
- CVE-2024-3330CRITICALCVSS 9.9EG 9.92024-06-27
Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being abl…
- CVE-2026-9209CRITICALCVSS 9.8EG 9.82026-10-08
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the…
- CVE-2026-89259CRITICALCVSS 9.8EG 9.82026-09-11
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --…
- CVE-2026-34877CRITICALCVSS 9.8EG 9.82026-04-02
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corr…
- CVE-2026-27002CRITICALCVSS 9.8EG 9.82026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sandbox could allow dangerous Docker options (bind mounts, host networking, unconfined profiles) to be applied, enabling co…
- CVE-2025-13375CRITICALCVSS 9.8EG 9.82026-02-04
IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.
- CVE-2025-12420CRITICALCVSS 9.8EG 9.82026-01-12
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed…
- CVE-2025-33224CRITICALCVSS 9.8EG 9.82025-12-23
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, …
- CVE-2025-33223CRITICALCVSS 9.8EG 9.82025-12-23
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, …
- CVE-2025-34274CRITICALCVSS 9.8EG 9.82025-10-30
Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash process - for exampl…
- CVE-2025-43017CRITICALCVSS 9.8EG 9.82025-10-28
HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.
- CVE-2025-34515CRITICALCVSS 9.8EG 9.82025-10-16
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulne…
- CVE-2025-57119CRITICALCVSS 9.8EG 9.82025-09-16
An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function
- CVE-2024-27143CRITICALCVSS 9.8EG 9.82024-06-14
Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will allow any attacker to get a root access on a remote Toshiba …
- CVE-2024-25421CRITICALCVSS 9.8EG 9.82024-03-26
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.
- CVE-2023-52030CRITICALCVSS 9.8EG 9.82024-01-11
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.
- CVE-2022-44544CRITICALCVSS 9.8EG 9.82022-11-06
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
- CVE-2021-41035CRITICALCVSS 9.8EG 9.82021-10-25
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
- CVE-2025-3364CRITICALCVSS 6.7EG 9.82025-04-08
The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system.
- CVE-2022-32535CRITICALCVSS 4.8EG 9.82022-06-23
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.
- CVE-2024-23743CRITICALCVSS 3.3EG 9.82024-01-28
Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron…
- CVE-2026-12027CRITICALCVSS 9.6EG 9.62026-06-11
Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severi…
- CVE-2026-11167CRITICALCVSS 9.6EG 9.62026-06-04
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium securi…
- CVE-2026-42088CRITICALCVSS 9.6EG 9.62026-05-04
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the …
- CVE-2024-7102CRITICALCVSS 9.6EG 9.62025-02-13
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.
- CVE-2026-87899CRITICALCVSS 9.4EG 9.42026-09-23
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
- CVE-2026-54501CRITICALCVSS 9.4EG 9.42026-09-17
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom…
- CVE-2026-42486CRITICALCVSS 9.4EG 9.42026-07-09
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, s…
- CVE-2026-23562CRITICALCVSS 9.4EG 9.42026-07-09
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, s…
- CVE-2026-23561CRITICALCVSS 9.4EG 9.42026-07-09
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, s…
- CVE-2026-23560CRITICALCVSS 9.4EG 9.42026-07-09
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, s…
- CVE-2026-23559CRITICALCVSS 9.4EG 9.42026-07-09
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details,…
- CVE-2025-67510CRITICALCVSS 9.4EG 9.42025-12-10
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is cons…
- CVE-2026-80238CRITICALCVSS 9.3EG 9.32026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially…
- CVE-2025-6949CRITICALCVSS 9.3EG 9.32025-10-17
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administr…
Map vulnerabilities like CWE-250 to your infrastructure
EchelonGraph correlates every CVE — across CWE-250 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →