CWE-648— Incorrect Use of Privileged APIs
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.— MITRE CWE catalog
68 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-648page 1 of 2
- CVE-2026-76460CRITICALCVSS 10.0EG 10.0⚠ KEV2026-09-16
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker…
- CVE-2026-20122CRITICALCVSS 5.4EG 9.0⚠ KEV2026-02-25
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credenti…
- CVE-2023-4972CRITICALCVSS 9.8EG 10.02023-09-14
Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This issue affects Digital Yepas: before 1.0.1.
- CVE-2026-41329CRITICALCVSS 9.9EG 9.92026-04-21
OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper context validation to by…
- CVE-2024-8785CRITICALCVSS 9.8EG 9.82024-12-02
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.
- CVE-2024-11068CRITICALCVSS 9.8EG 9.82024-11-11
The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services usin…
- CVE-2022-2023CRITICALCVSS 9.8EG 9.82022-06-20
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
- CVE-2019-14813CRITICALCVSS 9.8EG 9.82019-09-06
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could…
- CVE-2019-1010178CRITICALCVSS 9.8EG 9.82019-07-24
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets/components/fred/web/elfinder/connector.php. The attack vector is: Uploading a PHP file or…
- CVE-2026-41225CRITICALCVSS 9.1EG 9.12026-05-13
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached …
- CVE-2026-41386CRITICALCVSS 9.1EG 9.12026-04-28
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate pr…
- CVE-2024-37018CRITICALCVSS 9.1EG 9.12024-05-31
The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.
- CVE-2023-29507CRITICALCVSS 9.1EG 9.12023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent execu…
- CVE-2025-2311CRITICALCVSS 9.0EG 9.02025-03-20
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authent…
- CVE-2026-63727HIGHCVSS 8.8EG 8.82026-07-28
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API ca…
- CVE-2026-35669HIGHCVSS 8.8EG 8.82026-04-10
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope regardless of caller-granted scopes. Attackers can exploit this scope bo…
- CVE-2026-35663HIGHCVSS 8.8EG 8.82026-04-10
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request broader scopes during backend reconnect. Attackers can bypass pairing requirements to reconnect as operator.admin, gaining…
- CVE-2026-35639HIGHCVSS 8.8EG 8.82026-04-09
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually h…
- CVE-2025-54769HIGHCVSS 8.8EG 8.82025-07-29
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve r…
- CVE-2025-5997HIGHCVSS 8.8EG 8.82025-07-28
Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro: before 7.5.4.2.
- CVE-2025-7344HIGHCVSS 8.8EG 8.82025-07-21
The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to administrator level via a specific API.
- CVE-2023-28062HIGHCVSS 8.8EG 8.82023-04-11
Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and…
- CVE-2019-14869HIGHCVSS 8.8EG 8.82019-11-15
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw b…
- CVE-2026-20126HIGHCVSS 7.8EG 8.82026-02-25
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authenticati…
- CVE-2022-20956HIGHCVSS 7.1EG 8.82022-11-04
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access co…
- CVE-2022-26323HIGHCVSS 8.7EG 8.72025-04-17
Incorrect Use of Privileged APIs vulnerability in OpenText™ Operations Bridge Manager, OpenText™ Operations Bridge Suite (Containerized), OpenText™ UCMDB ( Classic and Containerized) allows Privilege Escalation. The vulnerability …
- CVE-2026-54424HIGHCVSS 8.4EG 8.42026-07-04
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A…
- CVE-2022-23720HIGHCVSS 7.5EG 8.22022-06-30
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, su…
- CVE-2026-35645HIGHCVSS 8.1EG 8.12026-04-09
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a synthetic operator.admin runtime scope. Attackers can exploit this by triggering session del…
- CVE-2022-4796HIGHCVSS 8.1EG 8.12022-12-28
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4687HIGHCVSS 8.1EG 8.12022-12-23
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
- CVE-2020-7927HIGHCVSS 8.1EG 8.12020-11-23
Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and including 4.2.17, MongoDB…
- CVE-2026-9560HIGHCVSS 7.8EG 7.82026-05-26
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
- CVE-2026-35625HIGHCVSS 7.8EG 7.82026-04-09
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permissions from operator.read to operator.admin. Attackers can e…
- CVE-2024-32008HIGHCVSS 7.8EG 7.82025-11-11
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any local …
- CVE-2025-23375HIGHCVSS 7.8EG 7.82025-04-28
Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of pri…
- CVE-2024-22042HIGHCVSS 7.8EG 7.82024-02-13
A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product contains incorrect use of privileged APIs that trigger the Windows Console Host (conhost.exe) as a child process with SYS…
- CVE-2019-14812HIGHCVSS 7.8EG 7.82019-11-27
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file co…
- CVE-2019-10216HIGHCVSS 7.8EG 7.82019-11-27
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript fil…
- CVE-2019-14817HIGHCVSS 7.8EG 7.82019-09-03
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript fil…
- CVE-2019-14811HIGHCVSS 7.8EG 7.82019-09-03
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file c…
- CVE-2019-3839HIGHCVSS 7.8EG 7.82019-05-16
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file syste…
- CVE-2026-11877HIGHCVSS 7.5EG 7.52026-06-24
An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.
- CVE-2025-54502HIGHCVSS 7.5EG 7.52026-04-16
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.
- CVE-2023-4993HIGHCVSS 7.5EG 7.52024-02-15
Incorrect Use of Privileged APIs vulnerability in Utarit Information Technologies SoliPay Mobile App allows Collect Data as Provided by Users. This issue affects SoliPay Mobile App: before 5.0.8.
- CVE-2023-6151HIGHCVSS 7.5EG 7.52023-11-28
Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided by Users. This issue affects e-municipality module: before v.105.
- CVE-2023-6150HIGHCVSS 7.5EG 7.52023-11-28
Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided by Users. This issue affects e-municipality module: before v.105.
- CVE-2023-6522HIGHCVSS 7.2EG 7.22024-04-05
Incorrect Use of Privileged APIs vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users. This issue affects Extreme XDS: before 3914.
- CVE-2023-4009HIGHCVSS 7.2EG 7.22023-08-08
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege es…
- CVE-2020-5291HIGHCVSS 7.2EG 7.22020-03-31
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable.…
Map vulnerabilities like CWE-648 to your infrastructure
EchelonGraph correlates every CVE — across CWE-648 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →