CWE-648
Low likelihoodIncorrect Use of Privileged APIs
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
61 vulnerabilities with CWE-648
CVE-2026-41386
CRITICAL
OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
CVSS 9.1
CVE-2026-41329
CRITICAL
OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
CVSS 9.9
CVE-2026-35669
HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope
CVSS 8.8
CVE-2026-35663
HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim
CVSS 8.8
CVE-2026-35645
HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
CVSS 8.1
CVE-2026-35639
HIGH
OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
CVSS 8.8
CVE-2026-35625
HIGH
OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect
CVSS 7.8
CVE-2026-20126
HIGH
Cisco Catalyst SD-WAN Manager - Privilege Escalation
CVSS 8.8
CVE-2026-20122
MEDIUM
KEV
Cisco Catalyst SD-WAN Manager - Path Traversal
CVSS 5.4
CVE-2026-22922
MEDIUM
Apache Airflow <3.1.6 - Info Disclosure
CVSS 6.5
CVE-2025-1161
HIGH
Nomysem - Privilege Escalation
CVSS 7.1
CVE-2025-63291
MEDIUM
Alteryx Server 2022.1.1.42654-2024.1 - Info Disclosure
CVSS 5.4
CVE-2025-54769
HIGH
Xorux Lpar2rrd < 8.04 - Remote Code Execution
CVSS 8.8
CVE-2025-54768
MEDIUM
API Endpoint - Info Disclosure
CVSS 5.3
CVE-2025-54767
MEDIUM
Xormon Original - Privilege Escalation
CVSS 6.5
CVE-2025-54766
MEDIUM
API - Info Disclosure
CVSS 5.3
CVE-2025-54765
MEDIUM
Xorux XorMon <= 1.8.0 - Privilege Escalation via API Endpoint
CVSS 5.3
CVE-2025-5997
HIGH
Beamsec PhishPro <7.5.4.2 - Privilege Escalation
CVSS 8.8
CVE-2025-7344
HIGH
Digiwin EAI - Privilege Escalation
CVSS 8.8
CVE-2025-23375
HIGH
Dell PowerProtect Data Manager Reporting <19.17 - Privilege Escalation
CVSS 7.8
CVE-2025-2311
CRITICAL
SecHard <3.3.0.20220411 - Privilege Escalation
CVSS 9.0
CVE-2025-0589
MEDIUM
Octopus Deploy - Info Disclosure
CVSS 5.3
CVE-2024-32008
HIGH
Spectrum Power 4 <V4.70 SP12 Update 2 - Privilege Escalation
CVSS 7.8
CVE-2024-53007
MEDIUM
Bentley Systems ProjectWise Integration Server <10.00.03.288 - SQL ...
CVSS 6.4
CVE-2024-8785
CRITICAL
WhatsUp Gold <2024.0.1 - RCE
CVSS 9.8
Details
Vulnerabilities
61
Exploit Likelihood
Low