VYPR

CWE-250

Execution with Unnecessary Privileges

BaseDraftLikelihood: Medium

Description

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-470 · CAPEC-69

CVEs mapped to this weakness (358)

page 16 of 18
  • CVE-2023-27312MedOct 12, 2023
    risk 0.35cvss 5.4epss 0.00

    SnapCenter Plugin for VMware vSphere versions 4.6 prior to 4.9 are susceptible to a vulnerability which may allow authenticated unprivileged users to modify email and snapshot name settings within the VMware vSphere user interface.

  • CVE-2025-62876MedNov 12, 2025
    risk 0.34cvss epss 0.00

    A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4.

  • CVE-2025-6894MedOct 17, 2025
    risk 0.34cvss epss 0.01

    An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping`…

  • CVE-2023-39261MedJul 26, 2023
    risk 0.34cvss 5.2epss 0.00

    In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions

  • CVE-2026-23528MedJan 16, 2026
    risk 0.33cvss 6.1epss 0.00

    Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which will result in code being executed by Jupyter due to a cross-side-scripting (XSS)…

  • CVE-2022-20676MedApr 15, 2022
    risk 0.33cvss 5.1epss 0.00

    A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root-level privileges. This vulnerability is due to insufficient input validation of data that is passed…

  • CVE-2026-22549MedFeb 4, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2025-32955MedApr 21, 2025
    risk 0.32cvss 6.0epss 0.00

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `disable-sudo` bypass. Harden-Runner includes a policy option `disable-sudo` to prevent the GitHub Actions runner user from using…

  • CVE-2023-42954MedMar 21, 2024
    risk 0.32cvss 4.9epss 0.00

    A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in…

  • CVE-2026-42890MedJun 12, 2026
    risk 0.31cvss epss 0.00

    Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the…

  • CVE-2025-36059MedJan 20, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system…

  • CVE-2024-8903MedSep 23, 2024
    risk 0.31cvss 4.7epss 0.00

    Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

  • CVE-2024-28005MedMar 28, 2024
    risk 0.31cvss 4.7epss 0.00

    Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N,…

  • CVE-2022-32535MedJun 23, 2022
    risk 0.31cvss 4.8epss 0.01

    The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.

  • CVE-2018-16888MedJan 14, 2019
    risk 0.31cvss 4.7epss 0.00

    It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned…

  • CVE-2025-62503MedOct 30, 2025
    risk 0.30cvss 4.6epss 0.00

    User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.

  • CVE-2026-20037MedFeb 25, 2026
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on an affected system. This vulnerability exists because unnecessary…

  • CVE-2025-42943MedAug 12, 2025
    risk 0.29cvss 4.5epss 0.00

    SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to…

  • CVE-2024-8266MedFeb 13, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

  • CVE-2023-37412MedJan 29, 2025
    risk 0.29cvss 4.4epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.