CWE-267— Privilege Defined With Unsafe Actions
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.— MITRE CWE catalog
70 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-267page 2 of 2
- CVE-2025-61754MEDIUMCVSS 6.5EG 6.52025-10-21
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with net…
- CVE-2025-7030MEDIUMCVSS 6.5EG 6.52025-07-08
Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.1…
- CVE-2020-7824MEDIUMCVSS 6.5EG 6.52020-08-25
A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vulnerability is due to insecure permission when handling session cookies. An attacker could …
- CVE-2023-27895MEDIUMCVSS 6.1EG 6.52023-03-14
SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device. The attacker could extract the currently views of the OTP and the secret OTP alphanum…
- CVE-2022-38124MEDIUMCVSS 5.7EG 6.52022-12-13
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.
- CVE-2025-62591MEDIUMCVSS 6.0EG 6.02025-10-21
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the i…
- CVE-2019-14865MEDIUMCVSS 5.9EG 5.92019-11-29
A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootab…
- CVE-2026-18858MEDIUMCVSS 5.5EG 5.52026-09-04
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
- CVE-2025-53070MEDIUMCVSS 5.5EG 5.52025-10-21
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where …
- CVE-2024-8631MEDIUMCVSS 5.5EG 5.52024-09-12
A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could hav…
- CVE-2017-2616MEDIUMCVSS 5.5EG 5.52018-07-27
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
- CVE-2025-13979MEDIUMCVSS 5.4EG 5.42026-01-28
Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.
- CVE-2025-62289MEDIUMCVSS 4.9EG 4.92025-10-21
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access…
- CVE-2025-62288MEDIUMCVSS 4.9EG 4.92025-10-21
Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Logger). Supported versions that are affected are 3.4.0.1.3 and 3.4.1.0.10. Easily exploitable vulnerability…
- CVE-2023-28049MEDIUMCVSS 4.7EG 4.72024-02-06
Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete.
- CVE-2025-47811MEDIUMCVSS 4.1EG 4.12025-07-10
In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web application itself offers several legitimate ways to execute arbitrary system commands (i.e.,…
- CVE-2026-6816LOWCVSS 3.8EG 3.82026-05-28
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
- CVE-2026-81161LOWCVSS 3.3EG 3.32026-09-02
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
- CVE-2025-62480LOWCVSS 2.7EG 2.72025-10-21
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network a…
- CVE-2025-62479LOWCVSS 2.7EG 2.72025-10-21
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network acce…
Map vulnerabilities like CWE-267 to your infrastructure
EchelonGraph correlates every CVE — across CWE-267 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →