CWE-250— Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.— MITRE CWE catalog
358 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-250page 8 of 8
- CVE-2026-59133HIGHCVSS 8.8EG 8.82026-08-11
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
- CVE-2026-67609HIGHCVSS 7.8EG 7.82026-08-03
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploi…
- CVE-2026-70496CRITICALCVSS 9.9EG 9.92026-08-19
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate…
- CVE-2026-71846MEDIUMCVSS 6.5EG 6.52026-08-12
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive p…
- CVE-2026-72508CRITICALCVSS 9.9EG 9.92026-08-12
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Reso…
- CVE-2026-76018HIGHCVSS 8.8EG 8.82026-08-20
Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)
- CVE-2026-8370HIGHCVSS 8.5EG 8.52026-05-19
Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 allows Privilege Escalation, Target Prog…
- CVE-2026-8933HIGHCVSS 7.8EG 7.82026-07-21
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affect…
Map vulnerabilities like CWE-250 to your infrastructure
EchelonGraph correlates every CVE — across CWE-250 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →