The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.
Volume of CVEs assigned to CWE-272 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-11492HIGH A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a mani | Jun 8, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-11497HIGH A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webs | Jun 8, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-15270HIGH A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web I | Jul 9, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-35535HIGH In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to p | Apr 3, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-15271HIGH A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functi | Jul 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-39459HIGH A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects | May 13, 2026 | 7.2 | 30 | NO | NO |
CVE-2026-32655HIGH Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially e | Apr 27, 2026 | 7.8 | 29 | NO | NO |
CVE-2025-59106HIGH The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an | Jan 26, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-11555HIGH A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulat | Jun 8, 2026 | 7.5 | 28 | NO | NO |
CVE-2021-26726HIGH A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: V | Feb 16, 2022 | 8.8 | 27 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.