CWE-250: Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
321 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-4606 — GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege
- CVE-2025-32445 — Users can gain privileged access to the host system and cluster with EventSource and Sensor CR
- CVE-2025-33224 — NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.
- CVE-2025-33223 — NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.
- CVE-2025-13375 — IBM Common Cryptographic Architecture Arbitrary Command Execution
- CVE-2024-27143 — Pre-authenticated Remote Code Execution
- CVE-2026-87506 — Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the r
- CVE-2025-67510 — MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
- CVE-2025-6949 — An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou
- CVE-2025-6893 — An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou
- CVE-2025-36356 — IBM Security Verify Access privilege escalation
- CVE-2025-34274 — Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges
- CVE-2025-12420 — Unauthenticated Privilege Escalation in ServiceNow AI Platform
- CVE-2024-43655 — Any authenticated users can execute OS commands as root using the <redacted>.sh CGI script.
- CVE-2024-43654 — Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station
- CVE-2024-43653 — Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station
- CVE-2024-43652 — Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station
- CVE-2024-43651 — Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station
- CVE-2024-43650 — Authenticated command injection in the <redacted> action leads to full remote code execution as root on the charging station
- CVE-2024-43649 — Authenticated command injection via <redacted>.exe <redacted> parameter
Recently published
- CVE-2026-79942 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-87506 — Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the r
- CVE-2026-80238 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-83534 — PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel()
- CVE-2026-72654 — Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure
- CVE-2026-76018 — Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engin
- CVE-2026-70496 — Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork
- CVE-2026-24183 — NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use imp
- CVE-2026-71846 — Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch beyond least privilege
- CVE-2026-72508 — Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)
- CVE-2026-17445 — IBM i is Affected By Improper Validation Vulnerability in Line Printer Daemon []
- CVE-2026-18669 — IBM i is Affected By A Privilege Escalation Vulnerability []
- CVE-2026-17110 — IBM i is Affected By Multiple Vulnerabilities in SQL
- CVE-2026-18982 — Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/admin clusterroles
- CVE-2026-18949 — Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resources
- CVE-2026-18608 — Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.org */*, and clusterrole/binding crud cluster-wide
- CVE-2026-48098 — NexTOR IP Changer Unsafely Uses sudo and shell=True
- CVE-2026-67609 — Telenia TVox 26.5.3 Privilege Escalation via Insecure sudoers Configuration
- CVE-2026-50737 — When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's
- CVE-2026-14172 — Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation