CWE-267

Privilege Defined With Unsafe Actions

Parent: CWE-269 - Improper Privilege Management

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

61 vulnerabilities with CWE-267
CVE-2025-7030 MEDIUM
Drupal TFA <1.11.0 - Privilege Escalation
CVSS 6.5
CVE-2025-2903 HIGH
Google Cloud Platform - Privilege Escalation
CVE-2025-23015 HIGH
Apache Cassandra <4.1.8 - Privilege Escalation
CVSS 8.8
CVE-2024-55968 HIGH
DTX DEC-M <6.1.1 - Privilege Escalation
CVSS 8.8
CVE-2024-9842 HIGH
Ivanti Secure Access Client < 22.7 - Incorrect Permission Assignment
CVSS 7.3
CVE-2024-8539 HIGH
Ivanti Secure Access Client <22.7R3 - Privilege Escalation
CVSS 7.1
CVE-2024-7571 HIGH
Ivanti Secure Access Client <22.7R4 - Privilege Escalation
CVSS 7.8
CVE-2024-47906 HIGH
Ivanti Connect Secure <22.7R2.3 - Privilege Escalation
CVSS 7.8
CVE-2024-8631 MEDIUM
GitLab EE - Privilege Escalation
CVSS 5.5
CVE-2024-5623 HIGH
B&R APROL <= R 4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-5622 HIGH
B&R APROL <4.2.07P3, <4.4-00P3 - Privilege Escalation
CVSS 7.8
CVE-2024-20411 MEDIUM
Cisco NX-OS Software - Privilege Escalation
CVSS 6.7
CVE-2024-42365 HIGH
Asterisk < 18.24.2 - Remote Code Execution
CVSS 7.4
CVE-2024-39866 HIGH
SINEMA Remote Connect Server <V3.2 SP1 - Privilege Escalation
CVSS 8.8
CVE-2024-32901 HIGH
Google Android - Out-of-Bounds Write
CVSS 7.8
CVE-2023-28049 MEDIUM
Dell Command | Monitor < 10.9.1 - Improper Privilege Management
CVSS 4.7
CVE-2023-41966 MEDIUM
Sielco Analog FM Transmitter Exc5000g... - Improper Privilege Management
CVSS 6.5
CVE-2023-43746 HIGH
BIG-IP - Privilege Escalation
CVSS 8.7
CVE-2023-44218 HIGH
Sonicwall Netextender < 10.2.336 - Privilege Escalation
CVSS 8.8
CVE-2023-32457 HIGH
Dell Powerscale Onefs < 9.2.1.22 - Improper Privilege Management
CVSS 7.5
CVE-2023-22647 CRITICAL
SUSE Rancher - Privilege Escalation
CVSS 9.9
CVE-2023-2983 HIGH
pimcore/pimcore <10.5.23 - Privilege Escalation
CVSS 8.8
CVE-2023-27895 MEDIUM
SAP Authenticator for Android -1.3.0 - Info Disclosure
CVSS 6.1
CVE-2022-38124 MEDIUM
Secomea SiteManager - Privilege Escalation
CVSS 5.7
CVE-2021-44547 CRITICAL
Odoo < 15.0 - Privilege Escalation
CVSS 9.1
Details
Vulnerabilities 61