CWE-648
Incorrect Use of Privileged APIs
Description
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-107 · CAPEC-234
CVEs mapped to this weakness (67)
page 4 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-20965 | Med | 0.28 | 4.3 | 0.01 | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control on a feature within… | ||
| CVE-2022-24071 | Med | 0.28 | 4.3 | 0.01 | Jan 28, 2022 | A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs. | ||
| CVE-2022-4805 | Med | 0.21 | 4.3 | 0.01 | Dec 28, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2026-63727 | Hig | 0.00 | 8.8 | 0.00 | Jul 28, 2026 | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions… | ||
| CVE-2026-54424 | Hig | 0.00 | 8.4 | 0.00 | Jul 4, 2026 | An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where… | ||
| CVE-2022-2023 | Cri | 0.00 | 9.8 | 0.03 | Jun 20, 2022 | Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4. | ||
| CVE-2020-5291 | Hig | 0.00 | 7.2 | 0.01 | Mar 31, 2020 | Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root… |
- risk 0.28cvss 4.3epss 0.01
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control on a feature within…
- risk 0.28cvss 4.3epss 0.01
A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs.
- risk 0.21cvss 4.3epss 0.01
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.00cvss 8.8epss 0.00
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions…
- risk 0.00cvss 8.4epss 0.00
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where…
- risk 0.00cvss 9.8epss 0.03
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
- risk 0.00cvss 7.2epss 0.01
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root…