CWE-267

Privilege Defined With Unsafe Actions

Parent: CWE-269 - Improper Privilege Management

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

59 vulnerabilities with CWE-267
CVE-2026-2460 HIGH
REB500 - Privilege Escalation
CVSS 8.1
CVE-2026-2459 HIGH
REB500 - Privilege Escalation
CVSS 8.1
CVE-2025-14349 HIGH
Universal Software Inc. FlexCity/Kiosk <1.0.36 - Privilege Escalation
CVSS 8.8
CVE-2026-0945 MEDIUM
Drupal Role Delegation <1.5.0 - Privilege Escalation
CVSS 5.4
CVE-2025-13979 MEDIUM
Salsa.digital Mini Site < 3.0.2 - XSS
CVSS 5.4
CVE-2026-23526 HIGH
CVAT <2.54.0 - Privilege Escalation
CVSS 8.8
CVE-2025-53900 MEDIUM
Kiteworks MFT <9.1.0 - Privilege Escalation
CVSS 6.5
CVE-2025-62641 HIGH
Oracle VM VirtualBox <7.2.2 - Privilege Escalation
CVSS 8.2
CVE-2025-62591 MEDIUM
Oracle VM VirtualBox <7.2.2 - Privilege Escalation
CVSS 6.0
CVE-2025-62590 HIGH
Oracle VM VirtualBox <7.2.2 - Privilege Escalation
CVSS 8.2
CVE-2025-62589 HIGH
Oracle VM VirtualBox <7.2.2 - Privilege Escalation
CVSS 8.2
CVE-2025-62588 HIGH
Oracle VM VirtualBox <7.2.2 - Privilege Escalation
CVSS 8.2
CVE-2025-62587 HIGH
Oracle VM VirtualBox <7.2.2 - Privilege Escalation
CVSS 8.2
CVE-2025-62480 LOW
Oracle Zfs Storage Appliance Kit - Denial of Service
CVSS 2.7
CVE-2025-62479 LOW
Oracle Zfs Storage Appliance Kit - Denial of Service
CVSS 2.7
CVE-2025-62289 MEDIUM
Oracle Zfs Storage Appliance Kit - Denial of Service
CVSS 4.9
CVE-2025-62288 MEDIUM
Oracle Health Sciences Data Management Workbench <3.4.1.0.10 - Unau...
CVSS 4.9
CVE-2025-61754 MEDIUM
Oracle Analytics Web Service API <8.2.0.0.0 - Unauthorized Access
CVSS 6.5
CVE-2025-53070 MEDIUM
Oracle Solaris - Denial of Service
CVSS 5.5
CVE-2025-41244 HIGHKEV
Vmware Aria Operations < 8.18.5 - Privilege Escalation
CVSS 7.8
CVE-2025-7691 MEDIUM
GitLab EE <18.2.7-<18.3.3-<18.4.1 - Privilege Escalation
CVSS 6.5
CVE-2025-26467 HIGH
Apache Cassandra <4.0.16 - Privilege Escalation
CVSS 8.8
CVE-2025-47811 MEDIUM
Wftpserver Wing FTP Server < 7.4.4 - Privilege Escalation
CVSS 4.1
CVE-2025-7030 MEDIUM
Drupal TFA <1.11.0 - Privilege Escalation
CVSS 6.5
CVE-2025-2903
Google Cloud Platform - Privilege Escalation
Details
Vulnerabilities 59