Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-268

Privilege Chaining

Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.

22
Assigned CVEs
322nd
Commonality Rank
7.4
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-268 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 26, 2019
7 years ago
Most Recent CVE
Jun 1, 2026
53 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-3888HIGH
Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automa
Mar 17, 20267.836NONO
CVE-2019-3844HIGH
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by
Apr 26, 20197.836NOYES
CVE-2025-49741HIGH
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Jul 1, 20257.534NOYES
CVE-2026-32325HIGH
Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the ser
Jun 1, 20267.832NONO
CVE-2025-7973HIGH
A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe cons
Aug 14, 20258.527NONO
CVE-2025-2297HIGH
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certai
Jul 28, 20257.827NONO
CVE-2023-0759HIGH
Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
Feb 9, 20238.827NONO
CVE-2023-0971HIGH
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be reco
Jun 21, 20238.826NONO
CVE-2025-36124HIGH
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configur
Aug 12, 20257.525NONO
CVE-2025-2903HIGH
An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control
Apr 17, 20258.525NONO
View all 22 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
9%
10%
4.0-4.9
19%
5.0-5.9
14%
16%
6.0-6.9
45%
26%
7.0-7.9
27%
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
9.1% of CVEs· 97th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products