A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
Volume of CVEs assigned to CWE-267 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
64 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-41244HIGH VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VM | Sep 29, 2025 | 7.8 | 73 | YES | NO |
CVE-2026-9560HIGH Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC ch | May 26, 2026 | 7.8 | 37 | NO | NO |
CVE-2024-42365HIGH Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 a | Aug 8, 2024 | 8.8 | 37 | NO | YES |
CVE-2026-42406HIGH A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects th | May 13, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-29646CRITICAL In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled inco | Apr 20, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-27314HIGH Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identi | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-62641HIGH Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulner | Oct 21, 2025 | 8.2 | 29 | NO | NO |
CVE-2025-14349HIGH Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Prope | Feb 13, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-62590HIGH Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulner | Oct 21, 2025 | 8.2 | 28 | NO | NO |
CVE-2025-62589HIGH Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulner | Oct 21, 2025 | 8.2 | 28 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.