CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2026-50737 CRITICAL
Enterprisedb Pglogical < 2.4.8 - Execution with Unnecessary Privileges
CVE-2026-14172 HIGH
Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation
CVSS 7.8
CVE-2026-14985 HIGH
Analog WAY Picturall Quad Compact Mark II < 3.5.9 - Privilege Escalation
CVSS 7.8
CVE-2026-8933 HIGH
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup
CVSS 7.8
CVE-2026-15226 HIGH
snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates
CVSS 8.4
CVE-2026-13104 HIGH
Lenovo App Store < 9.0.2930.0514 - Execution with Unnecessary Privileges
CVSS 7.3
CVE-2026-15584 HIGH
Pen Drive Powered BY Red Hat Lightspeed - Privilege Escalation
CVSS 7.5
CVE-2026-42486 CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-23562 CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-23561 CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-23560 CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-23559 CRITICAL
Multiple RBAC issues in XAPI
CVE-2026-54319 MEDIUM
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
CVSS 4.2
CVE-2026-48584 CRITICAL
Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVSS 9.9
CVE-2026-12505 HIGH
Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
CVSS 7.8
CVE-2026-47190 MEDIUM
IPAM controller service account granted unnecessary full access to Secrets
CVSS 4.4
CVE-2026-12027 CRITICAL
Google Chrome < 149.0.7827.115 - Sandbox Escape via Headless Inappropriate Implementation
CVSS 9.6
CVE-2026-11626 MEDIUM
Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool
CVE-2026-50566 CRITICAL
Fission < 1.24.0 Environment Validation - Privileged Pod Creation
CVSS 9.9
CVE-2026-50565 MEDIUM
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
CVSS 4.9
CVE-2026-46618 MEDIUM
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
CVE-2026-46617 HIGH
Fission < 1.23.0 Runtime Pods - Service Account Token Exposure
CVE-2026-46748 HIGH
Siemens Sinec Ins < V1.0 SP2 Update 6 - Execution with Unnecessary Privileges
CVSS 8.8
CVE-2026-11167 CRITICAL
Google Chrome < 149.0.7827.53 - Sandbox Escape via WebView
CVSS 9.6
CVE-2026-10843 HIGH
Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws
CVSS 7.2
Details
Vulnerabilities 341
Exploit Likelihood Medium