CWE-274: Improper Handling of Insufficient Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.
40 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-20156 — Cisco Meeting Management Client-Server Privilege Escalation Vulnerability
- CVE-2024-0105 — NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privi
- CVE-2024-0106 — NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker ma
- CVE-2024-41942 — JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
- CVE-2025-20177 — Cisco IOS XR Software Image Verification Bypass Vulnerability
- CVE-2024-12666 — ClassCMS User Management Page admin insufficient privileges
- CVE-2024-20324 — A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to acce
- CVE-2026-62764 — Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
- CVE-2025-54511 — Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp
- CVE-2025-62175 — Mastodon streaming API fails to disconnect disabled and suspended users
- CVE-2026-33005 — Apache OpenMeetings: Insufficient checks in FileWebService
- CVE-2024-46974 — GPU DDK - Arbitrary write of read-only dmabuf
Recently published
- CVE-2026-62764 — Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
- CVE-2025-54511 — Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp
- CVE-2026-33005 — Apache OpenMeetings: Insufficient checks in FileWebService
- CVE-2025-62175 — Mastodon streaming API fails to disconnect disabled and suspended users
- CVE-2025-20177 — Cisco IOS XR Software Image Verification Bypass Vulnerability
- CVE-2024-46974 — GPU DDK - Arbitrary write of read-only dmabuf
- CVE-2025-20156 — Cisco Meeting Management Client-Server Privilege Escalation Vulnerability
- CVE-2024-12666 — ClassCMS User Management Page admin insufficient privileges
- CVE-2024-0106 — NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker ma
- CVE-2024-0105 — NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privi
- CVE-2024-41942 — JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
- CVE-2024-20324 — A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to acce