CWE-250
Medium likelihoodExecution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
341 vulnerabilities with CWE-250
CVE-2026-50737
CRITICAL
Enterprisedb Pglogical < 2.4.8 - Execution with Unnecessary Privileges
CVE-2026-14172
HIGH
Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation
CVSS 7.8
CVE-2026-14985
HIGH
Analog WAY Picturall Quad Compact Mark II < 3.5.9 - Privilege Escalation
CVSS 7.8
CVE-2026-8933
HIGH
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
CVSS 7.8
CVE-2026-15226
HIGH
snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates
CVSS 8.4
CVE-2026-13104
HIGH
Lenovo App Store < 9.0.2930.0514 - Execution with Unnecessary Privileges
CVSS 7.3
CVE-2026-15584
HIGH
Pen Drive Powered BY Red Hat Lightspeed - Privilege Escalation
CVSS 7.5
CVE-2026-42486
CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-23562
CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-23561
CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-23560
CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-23559
CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-54319
MEDIUM
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
CVSS 4.2
CVE-2026-48584
CRITICAL
Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVSS 9.9
CVE-2026-12505
HIGH
Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
CVSS 7.8
CVE-2026-47190
MEDIUM
IPAM controller service account granted unnecessary full access to Secrets
CVSS 4.4
CVE-2026-12027
CRITICAL
Google Chrome < 149.0.7827.115 - Sandbox Escape via Headless Inappropriate Implementation
CVSS 9.6
CVE-2026-11626
MEDIUM
Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool
CVE-2026-50566
CRITICAL
Fission < 1.24.0 Environment Validation - Privileged Pod Creation
CVSS 9.9
CVE-2026-50565
MEDIUM
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
CVSS 4.9
CVE-2026-46618
MEDIUM
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
CVE-2026-46617
HIGH
Fission < 1.23.0 Runtime Pods - Service Account Token Exposure
CVE-2026-46748
HIGH
Siemens Sinec Ins < V1.0 SP2 Update 6 - Execution with Unnecessary Privileges
CVSS 8.8
CVE-2026-11167
CRITICAL
Google Chrome < 149.0.7827.53 - Sandbox Escape via WebView
CVSS 9.6
CVE-2026-10843
HIGH
Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws
CVSS 7.2
Details
Vulnerabilities
341
Exploit Likelihood
Medium