VYPR

CWE-250

Execution with Unnecessary Privileges

BaseDraftLikelihood: Medium

Description

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-470 · CAPEC-69

CVEs mapped to this weakness (358)

page 1 of 18
  • CVE-2025-12420CriJan 12, 2026
    risk 0.67cvss 9.8epss 0.46

    A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a…

  • CVE-2026-4606CriMar 23, 2026
    risk 0.65cvss epss 0.00

    GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system.  During installation, ERM creates a Windows service that runs under the LocalSystem account.  …

  • CVE-2022-2634CriAug 10, 2022
    risk 0.65cvss 10.0epss 0.01

    An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploading python files which can be later executed.

  • CVE-2022-1517CriJun 24, 2022
    risk 0.65cvss 10.0epss 0.02

    LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on the affected produc. An attacker could…

  • CVE-2026-72508CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly…

  • CVE-2026-48584CriJun 19, 2026
    risk 0.64cvss 9.9epss 0.01

    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-25212CriApr 2, 2026
    risk 0.64cvss 9.9epss 0.00

    An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying…

  • CVE-2025-13375CriFeb 4, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.

  • CVE-2025-33224CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data…

  • CVE-2025-33223CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data…

  • CVE-2025-34274CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.02

    Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash process - for example by exploiting an insecure plugin,…

  • CVE-2025-43017CriOct 28, 2025
    risk 0.64cvss 9.8epss 0.00

    HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.

  • CVE-2025-34515CriOct 16, 2025
    risk 0.64cvss 9.8epss 0.07

    Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers…

  • CVE-2025-57119CriSep 16, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function

  • CVE-2024-8767CriSep 17, 2024
    risk 0.64cvss 9.9epss 0.00

    Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for…

  • CVE-2024-3330CriJun 27, 2024
    risk 0.64cvss 9.9epss 0.01

    Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of this vulnerability will result in an attacker being able to run arbitrary code.This requires…

  • CVE-2024-27143CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will allow any attacker to get a root access on a remote Toshiba printer. This vulnerability can be…

  • CVE-2023-52030CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.

  • CVE-2023-4662CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: before 9.

  • CVE-2022-44544CriNov 6, 2022
    risk 0.64cvss 9.8epss 0.01

    Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.