CWE-273: Improper Check for Dropped Privileges
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
19 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-1003 — HP Anyware Agent for Linux – Potential Authentication Bypass
- CVE-2026-21882 — theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution
- CVE-2025-27396 — A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
- CVE-2026-32107 — xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails
- CVE-2026-60085 — PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
- CVE-2026-58086 — ktrace(2) privilege incorrectly validated in jails
- CVE-2026-54552 — sh _uid does not drop supplementary groups (incomplete privilege drop)
- CVE-2026-61897 — accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
- CVE-2026-58089 — hwpmc fails to detach PMCs during exec credential transitions
- CVE-2026-49421 — unlinkat(2) ignores AT_RESOLVE_BENEATH flag
- CVE-2025-62175 — Mastodon streaming API fails to disconnect disabled and suspended users
- CVE-2026-44073 — seteuid failure ignored in auth modules
Recently published
- CVE-2026-58089 — hwpmc fails to detach PMCs during exec credential transitions
- CVE-2026-61897 — accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
- CVE-2026-58086 — ktrace(2) privilege incorrectly validated in jails
- CVE-2026-49421 — unlinkat(2) ignores AT_RESOLVE_BENEATH flag
- CVE-2026-54552 — sh _uid does not drop supplementary groups (incomplete privilege drop)
- CVE-2026-60085 — PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
- CVE-2026-44073 — seteuid failure ignored in auth modules
- CVE-2026-32107 — xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails
- CVE-2026-21882 — theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution
- CVE-2025-62175 — Mastodon streaming API fails to disconnect disabled and suspended users
- CVE-2025-27396 — A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
- CVE-2025-1003 — HP Anyware Agent for Linux – Potential Authentication Bypass