VYPR

CWE-267

Privilege Defined With Unsafe Actions

BaseIncomplete

Description

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-58 · CAPEC-634 · CAPEC-637 · CAPEC-643 · CAPEC-648

CVEs mapped to this weakness (65)

page 4 of 4
  • CVE-2025-62480LowOct 21, 2025
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS…

  • CVE-2025-62479LowOct 21, 2025
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS…

  • CVE-2024-42365HigAug 8, 2024
    risk 0.03cvss 7.4epss 0.05

    Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all configuration files in the…

  • CVE-2026-23526HigJan 21, 2026
    risk 0.00cvss 8.8epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their permissions, including giving themselves superuser status and joining the admin group, which gives…

  • CVE-2017-2616MedJul 27, 2018
    risk 0.00cvss 5.5epss 0.00

    A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.