VYPR

CWE-250

Execution with Unnecessary Privileges

BaseDraftLikelihood: Medium

Description

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-470 · CAPEC-69

CVEs mapped to this weakness (375)

page 17 of 19
  • CVE-2024-20420MedOct 16, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with low privileges to run commands as an Admin user. This vulnerability is due to incorrect authorization…

  • CVE-2023-27312MedOct 12, 2023
    risk 0.35cvss 5.4epss 0.00

    SnapCenter Plugin for VMware vSphere versions 4.6 prior to 4.9 are susceptible to a vulnerability which may allow authenticated unprivileged users to modify email and snapshot name settings within the VMware vSphere user interface.

  • CVE-2018-10892MedJul 6, 2018
    risk 0.35cvss 5.3epss 0.01

    The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

  • CVE-2025-62876MedNov 12, 2025
    risk 0.34cvss —epss 0.00

    A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4.

  • CVE-2025-6894MedOct 17, 2025
    risk 0.34cvss —epss 0.01

    An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping`…

  • CVE-2023-39261MedJul 26, 2023
    risk 0.34cvss 5.2epss 0.00

    In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions

  • CVE-2026-23528MedJan 16, 2026
    risk 0.33cvss 6.1epss 0.00

    Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which will result in code being executed by Jupyter due to a cross-side-scripting (XSS)…

  • CVE-2022-20676MedApr 15, 2022
    risk 0.33cvss 5.1epss 0.00

    A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root-level privileges. This vulnerability is due to insufficient input validation of data that is passed…

  • CVE-2026-22549MedFeb 4, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2025-32955MedApr 21, 2025
    risk 0.32cvss 6.0epss 0.00

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `disable-sudo` bypass. Harden-Runner includes a policy option `disable-sudo` to prevent the GitHub Actions runner user from using…

  • CVE-2023-42954MedMar 21, 2024
    risk 0.32cvss 4.9epss 0.00

    A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in…

  • CVE-2026-42890MedJun 12, 2026
    risk 0.31cvss —epss 0.00

    Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the…

  • CVE-2025-36059MedJan 20, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system…

  • CVE-2024-8903MedSep 23, 2024
    risk 0.31cvss 4.7epss 0.00

    Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

  • CVE-2024-28005MedMar 28, 2024
    risk 0.31cvss 4.7epss 0.00

    Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N,…

  • CVE-2022-32535MedJun 23, 2022
    risk 0.31cvss 4.8epss 0.01

    The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.

  • CVE-2018-16888MedJan 14, 2019
    risk 0.31cvss 4.7epss 0.00

    It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned…

  • CVE-2025-62503MedOct 30, 2025
    risk 0.30cvss 4.6epss 0.00

    User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.

  • CVE-2026-19087MedSep 23, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.

  • CVE-2026-20037MedFeb 25, 2026
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on an affected system. This vulnerability exists because unnecessary…