Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.
Volume of CVEs assigned to CWE-268 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3888HIGH Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automa | Mar 17, 2026 | 7.8 | 36 | NO | NO |
CVE-2019-3844HIGH It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2025-49741HIGH No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | Jul 1, 2025 | 7.5 | 34 | NO | YES |
CVE-2026-32325HIGH Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the ser | Jun 1, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-7973HIGH A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe cons | Aug 14, 2025 | 8.5 | 27 | NO | NO |
CVE-2025-2297HIGH Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certai | Jul 28, 2025 | 7.8 | 27 | NO | NO |
CVE-2023-0759HIGH Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. | Feb 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-0971HIGH A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be reco | Jun 21, 2023 | 8.8 | 26 | NO | NO |
CVE-2025-36124HIGH IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configur | Aug 12, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-2903HIGH An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control | Apr 17, 2025 | 8.5 | 25 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.