CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2026-21426 MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2026-21424 MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2026-21421 MEDIUM
Dell PowerScale OneFS <9.10.1.6/9.11.0.0-9.12.0.1 - Privilege Escal...
CVSS 6.7
CVE-2026-21882 HIGH
theshit <0.2.0 - Privilege Escalation
CVSS 8.4
CVE-2026-20037 MEDIUM
Cisco UCS Manager - Privilege Escalation
CVSS 4.4
CVE-2026-27208 CRITICAL
bleon-ethical/api-gateway-deploy 1.0.0 - Command Injection
CVSS 9.2
CVE-2026-27002 CRITICAL
OpenClaw <2026.2.15 - Privilege Escalation
CVSS 9.8
CVE-2026-25740 MEDIUM
Captive Browser <25.11-26.05 - Command Injection
CVE-2026-0870 HIGH
GIGABYTE MacroHub < 2.3.1 - Authenticated Local Privilege Escalation via Improper Privilege Management
CVSS 7.8
CVE-2026-25643 CRITICAL
Frigate < 0.16.4 - Remote Command Execution via go2rtc exec Directive
CVSS 9.1
CVE-2026-22549 MEDIUM
F5 BIG-IP Container Ingress Services 1.0.0-1.13.9 - Unauthenticated Excessive Privilege Assignment
CVSS 4.9
CVE-2026-1680 HIGH
Edgemo Local Admin Service 1.2.7.23180 - Privilege Escalation
CVSS 7.8
CVE-2026-23742 HIGH
Skipper < 0.23.0 - Unauthenticated Information Disclosure via Lua Filter Script Injection
CVSS 8.8
CVE-2026-23528 MEDIUM
Dask distributed < 2026.1.0 - Cross-Site Scripting via Jupyter Lab Dashboard Proxy
CVSS 6.1
CVE-2025-12694 HIGH
Forcepoint - Local Privilege Escalation in VPN Client
CVSS 7.8
CVE-2025-69783 HIGH
OpenEDR 2.5.1.0 - Privilege Escalation
CVSS 7.8
CVE-2025-12690 HIGH
Forcepoint NGFW Engine <=7.3.0 - Privilege Escalation
CVSS 7.8
CVE-2025-1790 MEDIUM
Genetec Sipelia Plugin - Privilege Escalation
CVE-2025-13375 CRITICAL
IBM CCA 7.5.52-8.4.82 - Privilege Escalation
CVSS 9.8
CVE-2025-58383 HIGH
Brocade Fabric OS <9.2.1c2 - Privilege Escalation
CVSS 7.2
CVE-2025-58379 MEDIUM
Brocade Fabric OS <9.2.1 - Info Disclosure
CVSS 5.5
CVE-2025-36184 HIGH
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 1...
CVSS 7.2
CVE-2025-36059 MEDIUM
IBM Business Automation Workflow <25.0.0-24.0.0 - Privilege Escalation
CVSS 4.7
CVE-2025-40942 HIGH
TeleControl Server Basic < 3.1.2.4 - Local Privilege Escalation
CVSS 8.8
CVE-2025-12420 CRITICAL
ServiceNow AI Platform - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 341
Exploit Likelihood Medium