CWE-648

Low likelihood

Incorrect Use of Privileged APIs

Parent: CWE-269 - Improper Privilege Management

The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

63 vulnerabilities with CWE-648
CVE-2026-9560 HIGH
OpenVPN Connect < 3.8.1 - Privilege Defined With Unsafe Actions
CVSS 7.8
CVE-2026-41225 CRITICAL
F5 BIG-IP 16.1.0-17.1.3.1/17.5.0-17.5.1.5/21.0.0-21.0.0.1/>=21.1.0 - Authenticated RCE via iControl REST
CVSS 9.1
CVE-2026-41386 CRITICAL
OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
CVSS 9.1
CVE-2026-41329 CRITICAL
OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
CVSS 9.9
CVE-2026-35669 HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope
CVSS 8.8
CVE-2026-35663 HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim
CVSS 8.8
CVE-2026-35645 HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
CVSS 8.1
CVE-2026-35639 HIGH
OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
CVSS 8.8
CVE-2026-35625 HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect
CVSS 7.8
CVE-2026-20126 HIGH
Cisco Catalyst SD-WAN Manager - Privilege Escalation
CVSS 8.8
CVE-2026-20122 MEDIUM KEV
Cisco Catalyst SD-WAN Manager - Path Traversal
CVSS 5.4
CVE-2026-22922 MEDIUM
Apache Airflow <3.1.6 - Info Disclosure
CVSS 6.5
CVE-2025-1161 HIGH
Nomysem <= May 2025 - Privilege Escalation via Incorrect Use of Privileged APIs
CVSS 7.1
CVE-2025-63291 MEDIUM
Alteryx Server 2022.1.1.42654-2024.1 - Info Disclosure
CVSS 5.4
CVE-2025-54769 HIGH
lpar2rrd < 8.04 - Authenticated Directory Traversal and Remote Code Execution via File Upload
CVSS 8.8
CVE-2025-54768 MEDIUM
lpar2rrd < 8.04 - Unauthenticated Sensitive Information Exposure via Privileged API Endpoint
CVSS 5.3
CVE-2025-54767 MEDIUM
Xormon Original - Privilege Escalation
CVSS 6.5
CVE-2025-54766 MEDIUM
xorux xormon < 1.8.0 - Unauthenticated Sensitive Information Exposure via Privileged API Endpoint
CVSS 5.3
CVE-2025-54765 MEDIUM
Xorux XorMon <= 1.8.0 - Privilege Escalation via API Endpoint
CVSS 5.3
CVE-2025-5997 HIGH
Beamsec PhishPro <7.5.4.2 - Privilege Escalation
CVSS 8.8
CVE-2025-7344 HIGH
Digiwin EAI < 2.5.1 build 0161 - Privilege Escalation via Specific API
CVSS 8.8
CVE-2025-23375 HIGH
Dell PowerProtect Data Manager Reporting <19.17 - Privilege Escalation
CVSS 7.8
CVE-2025-2311 CRITICAL
SecHard <3.3.0.20220411 - Privilege Escalation
CVSS 9.0
CVE-2025-0589 MEDIUM
Octopus Server 2020.3.3-2024.3.13071 - Unauthenticated Information Disclosure via Active Directory API Endpoints
CVSS 5.3
CVE-2024-32008 HIGH
Spectrum Power 4 <V4.70 SP12 Update 2 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 63
Exploit Likelihood Low