CWE-267: Privilege Defined With Unsafe Actions
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
53 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-41244 — VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
- CVE-2024-39866 — A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application
- CVE-2026-23526 — CVAT vulnerable to privilege escalation of users with staff status
- CVE-2025-2903 — Privilege Chaining in Delphix
- CVE-2024-47906 — Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy
- CVE-2026-10090 — Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
- CVE-2024-42365 — Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
- CVE-2026-27314 — Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
- CVE-2025-14349 — Business Logic Error in Universal Software's FlexCity/Kiosk
- CVE-2024-9842 — Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to crea
- CVE-2024-5622 — Untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL
- CVE-2026-42406 — BIG-IP and BIG-IQ privilege escalation vulnerability
- CVE-2025-7691 — Privilege Defined With Unsafe Actions in GitLab
- CVE-2025-53900 — Kiteworks MFT has a Privilege Defined With Unsafe Actions
- CVE-2025-36255 — DS8900F and DS8A00 Privilege Escalation
- CVE-2024-5623 — Untrusted search path vulnerability in B&R APROL
- CVE-2026-6816 — TFA Basic Plugins - Access Bypass
- CVE-2025-47811 — In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or S
- CVE-2026-81161 — Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
Recently published
- CVE-2026-18858 — IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []
- CVE-2026-81161 — Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
- CVE-2025-36255 — DS8900F and DS8A00 Privilege Escalation
- CVE-2026-10090 — Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription
- CVE-2026-6816 — TFA Basic Plugins - Access Bypass
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
- CVE-2026-42406 — BIG-IP and BIG-IQ privilege escalation vulnerability
- CVE-2026-27314 — Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
- CVE-2025-14349 — Business Logic Error in Universal Software's FlexCity/Kiosk
- CVE-2026-0945 — Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002
- CVE-2025-13979 — Mini site - Moderately critical - Cross-Site Scripting - SA-CONTRIB-2025-117
- CVE-2026-23526 — CVAT vulnerable to privilege escalation of users with staff status
- CVE-2025-53900 — Kiteworks MFT has a Privilege Defined With Unsafe Actions
- CVE-2025-41244 — VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
- CVE-2025-7691 — Privilege Defined With Unsafe Actions in GitLab
- CVE-2025-26467 — Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)
- CVE-2025-47811 — In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or S
- CVE-2025-7030 — Two-factor Authentication (TFA) - Less critical - Access bypass - SA-CONTRIB-2025-085
- CVE-2025-2903 — Privilege Chaining in Delphix
- CVE-2025-23015 — Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
More specific weaknesses
- CWE-623 — Unsafe ActiveX Control Marked Safe For Scripting