CWE-272: Least Privilege Violation
The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.
38 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-24830 — OpenObserve Privilege Escalation Vulnerability in Users API
- CVE-2024-28824 — Privilege escalation in mk_informix plugin
- CVE-2025-8181 — TOTOLINK N600R/X2000R FTP Service vsftpd.conf least privilege violation
- CVE-2025-9711 — Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b
- CVE-2024-0638 — Privilege escalation in mk_oracle plugins
- CVE-2024-0798 — Privilege Escalation in mintplex-labs/anything-llm
- CVE-2024-27165 — Local Privilege Escalation
- CVE-2025-7722 — Social Streams <= 1.2.1 - Authenticated (Subscriber+) Privilege Escalation
- CVE-2025-8758 — TRENDnet TEW-822DRE vsftpd least privilege violation
- CVE-2025-8757 — TRENDnet TV-IP110WN Embedded Boa Web Server boa.conf least privilege violation
- CVE-2025-49144 — Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path
- CVE-2026-39459 — iControl REST and tmsh vulnerability
- CVE-2025-1384 — Least Privilege Violation Vulnerability in the communications functions of NJ/NX-series Machine Automation Controllers
- CVE-2025-47809 — Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reb
- CVE-2025-68267 — In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token in
- CVE-2026-15271 — TOTOLINK EX200 Web boa.conf least privilege violation
- CVE-2026-15270 — D-link DIR-823G Web boa.conf least privilege violation
- CVE-2026-59915 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A
- CVE-2026-11620 — TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation
- CVE-2026-11497 — D-Link DCS-5615 Boa Webserver boa.conf least privilege violation
Recently published
- CVE-2026-79693 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79944 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2025-62299 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-59915 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A
- CVE-2026-49500 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Acces
- CVE-2026-15271 — TOTOLINK EX200 Web boa.conf least privilege violation
- CVE-2026-15270 — D-link DIR-823G Web boa.conf least privilege violation
- CVE-2026-11620 — TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation
- CVE-2026-11555 — D-Link DGS-1100-08PD Web boa.conf least privilege violation
- CVE-2026-11554 — TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation
- CVE-2026-11497 — D-Link DCS-5615 Boa Webserver boa.conf least privilege violation
- CVE-2026-11494 — TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation
- CVE-2026-11492 — D-Link DIR-823G vsftpd vsftpd.conf least privilege violation
- CVE-2026-39459 — iControl REST and tmsh vulnerability
- CVE-2026-32655 — Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A l
- CVE-2025-9711 — Privilege escalation in Brocade Fabric OS before 9.2.1c3, and 9.2.2 though 9.2.2b
- CVE-2025-59106 — Web Server Running with Root Privileges in dormakaba access manager
- CVE-2026-23634 — Pepr Overly Permissive RBAC ClusterRole in Admin Mode
- CVE-2025-68267 — In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token in
- CVE-2025-8758 — TRENDnet TEW-822DRE vsftpd least privilege violation