CWE-270: Privilege Context Switching Error
The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.
26 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-49581 — XWiki allows remote code execution through default value of wiki macro wiki-type parameters
- CVE-2025-9408 — Userspace privilege escalation vulnerability on Cortex M
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
- CVE-2024-36513 — A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.
- CVE-2024-12570 — Privilege Context Switching Error in GitLab
- CVE-2026-34853 — Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect avai
- CVE-2025-26499 — Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This
- CVE-2025-46406 — A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high l
- CVE-2024-47173 — Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups
- CVE-2024-37294 — Aimeos denial of service vulnerability in SaaS and marketplace setups
- CVE-2024-51987 — HTTP Client uses incorrect token after refresh in Duende.AccessTokenManagement.OpenIdConnect
- CVE-2025-49583 — XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
- CVE-2025-55210 — FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes
- CVE-2024-46975 — GPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mapping
Recently published
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
- CVE-2026-34853 — Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect avai
- CVE-2025-55210 — FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes
- CVE-2025-9408 — Userspace privilege escalation vulnerability on Cortex M
- CVE-2025-26499 — Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This
- CVE-2025-46406 — A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high l
- CVE-2025-49583 — XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
- CVE-2025-49581 — XWiki allows remote code execution through default value of wiki macro wiki-type parameters
- CVE-2024-46975 — GPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mapping
- CVE-2024-12570 — Privilege Context Switching Error in GitLab
- CVE-2024-36513 — A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.
- CVE-2024-51987 — HTTP Client uses incorrect token after refresh in Duende.AccessTokenManagement.OpenIdConnect
- CVE-2024-47173 — Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups
- CVE-2024-37294 — Aimeos denial of service vulnerability in SaaS and marketplace setups