CWE-648: Incorrect Use of Privileged APIs
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
63 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-7344 — Digiwin|EAI - Privilege Escalation
- CVE-2024-32008 — A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i
- CVE-2025-23375 — Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability
- CVE-2024-22042 — A vulnerability has been identified in Unicam FX (All versions). The windows installer agent used in affected product co
- CVE-2026-41386 — OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
- CVE-2026-41329 — OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
- CVE-2025-2311 — Authentication Bypass in Sechard Information Technologies' SecHard
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
- CVE-2025-5997 — Privilege Escalation in Beamsec PhishPro
- CVE-2026-63727 — Anchore Enterprise Privilege Escalation via User Management API
- CVE-2026-35669 — OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope
- CVE-2026-35663 — OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim
- CVE-2026-35639 — OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
- CVE-2026-41225 — iControl REST vulnerability
- CVE-2026-35625 — OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect
- CVE-2026-54424 — An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri
- CVE-2024-46978 — Missing checks for notification filter preferences editions in XWiki Platform
- CVE-2024-53007 — Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authentic
- CVE-2025-1161 — Improper Authorization in Nomysoft Informatics' Nomysem
- CVE-2026-11877 — Missing Authorization Vulnerability in OpenText Access Manager
Recently published
- CVE-2026-63727 — Anchore Enterprise Privilege Escalation via User Management API
- CVE-2026-54424 — An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri
- CVE-2026-11877 — Missing Authorization Vulnerability in OpenText Access Manager
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
- CVE-2026-41225 — iControl REST vulnerability
- CVE-2026-41386 — OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
- CVE-2026-41329 — OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
- CVE-2026-35669 — OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope
- CVE-2026-35663 — OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim
- CVE-2026-35645 — OpenClaw < 2026.3.25 - Privilege Escalation via Synthetic operator.admin in deleteSession
- CVE-2026-35639 — OpenClaw < 2026.3.22 - Privilege Escalation via device.pair.approve Scope Validation
- CVE-2026-35625 — OpenClaw < 2026.3.25 - Privilege Escalation via Silent Local Shared-Auth Reconnect
- CVE-2026-22922 — Apache Airflow: Airflow externalLogUrl Permission Bypass
- CVE-2025-1161 — Improper Authorization in Nomysoft Informatics' Nomysem
- CVE-2024-32008 — A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i
- CVE-2025-54769 — KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
- CVE-2025-54768 — KL-001-2025-015: Xorux LPAR2RRD Read Only User Log Download Exposing Sensitive Information
- CVE-2025-54767 — KL-001-2025-014: Xorux LPAR2RRD Read Only User Denial of Service
- CVE-2025-54765 — KL-001-2025-013: Xorux XorMon-NG Web Application Privilege Escalation to Administrator
- CVE-2025-54766 — KL-001-2025-012: Xorux XorMon-NG Read Only User Export Device Configuration Exposing Sensitive Information