VYPR

CWE-250

Execution with Unnecessary Privileges

BaseDraftLikelihood: Medium

Description

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-470 · CAPEC-69

CVEs mapped to this weakness (373)

page 14 of 19
  • CVE-2026-21424MedMar 4, 2026
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…

  • CVE-2026-21421MedMar 4, 2026
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of…

  • CVE-2025-37128MedSep 16, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an…

  • CVE-2025-21110MedAug 14, 2025
    risk 0.44cvss 6.7epss 0.00

    Dell Data Lakehouse, versions prior to 1.5.0.0, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2025-3892MedAug 12, 2025
    risk 0.44cvss 6.7epss 0.00

    ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to…

  • CVE-2025-43487MedJul 23, 2025
    risk 0.44cvss 6.8epss 0.00

    A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not properly implement access controls. HP has addressed the issue in the latest software update.

  • CVE-2025-3364MedApr 8, 2025
    risk 0.44cvss 6.7epss 0.00

    The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system.

  • CVE-2024-27146MedJun 14, 2024
    risk 0.44cvss 6.7epss 0.00

    The Toshiba printers do not implement privileges separation. As for the affected products/models/versions, see the reference URL.

  • CVE-2024-25967MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-45592MedMar 5, 2024
    risk 0.44cvss 6.8epss 0.01

    A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root privileges) exacerbates the impacts of successful attacks executed against the browser. This…

  • CVE-2023-32486MedAug 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

  • CVE-2023-2002MedMay 26, 2023
    risk 0.44cvss 6.8epss 0.01

    A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and…

  • CVE-2022-1744MedJun 24, 2022
    risk 0.44cvss 6.8epss 0.00

    Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by exploiting a system level service. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code.

  • CVE-2020-10290MedAug 21, 2020
    risk 0.44cvss 6.8epss 0.00

    Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate…

  • CVE-2020-10684HigMar 24, 2020
    risk 0.44cvss 7.9epss 0.00

    A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker…

  • CVE-2026-4498HigApr 8, 2026
    risk 0.43cvss 7.7epss 0.00

    Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges…

  • CVE-2025-5196MedMay 26, 2025
    risk 0.43cvss 6.6epss 0.01

    A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Lua Admin Console. The manipulation leads to execution with unnecessary privileges. The attack can be launched…

  • CVE-2026-69409MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  • CVE-2026-83534MedSep 6, 2026
    risk 0.42cvss 6.4epss 0.00

    PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions

  • CVE-2026-71846MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the…