CWE-250 带着不必要的权限执行 类弱点 245 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-250指程序以高于实际所需的最小权限级别执行操作。这种过度授权不仅可能直接引发权限提升漏洞,还会放大其他安全缺陷的后果。攻击者常利用此弱点,通过触发特定功能获取更高系统控制权,从而执行恶意代码或窃取敏感数据。开发者应遵循最小权限原则,在代码中严格限制进程权限,确保仅授予完成任务所必需的最低特权,从而降低潜在安全风险。
def makeNewUserDir(username): if invalidUsername(username): #avoid CWE-22 and CWE-78 print('Usernames cannot contain invalid characters') return False try: raisePrivileges() os.mkdir('/home/' + username) lowerPrivileges() except OSError: print('Unable to create new user directory for user:' + username) return False return Truechroot(APP_HOME); chdir("/"); FILE* data = fopen(argv[1], "r+"); ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-44477 | CloudNativePG 代码问题漏洞 — cloudnative-pg | - | - | 2026-05-28 |
| CVE-2026-3623 | IBM Netezza Performance Server Replication Services 安全漏洞 — Netezza Performance Server Replication Services | 7.8 | High | 2026-05-27 |
| CVE-2026-8370 | Broadcom Automic Automation Agent 安全漏洞 — Automic Automation | - | - | 2026-05-19 |
| CVE-2026-29205 | cPanel 安全漏洞 — cPanel | 8.6 | High | 2026-05-13 |
| CVE-2026-32643 | F5 BIG-IP和F5 BIG-IQ 安全漏洞 — BIG-IP | 6.5 | Medium | 2026-05-13 |
| CVE-2026-32673 | F5 BIG-IP 安全漏洞 — BIG-IP | 8.7 | High | 2026-05-13 |
| CVE-2026-25710 | Plasma Workspace 安全漏洞 — plasma-login-manager | - | - | 2026-05-13 |
| CVE-2026-42833 | Microsoft Dynamics 365 安全漏洞 — Microsoft Dynamics 365 (on-premises) version 9.1 | 9.1 | Critical | 2026-05-12 |
| CVE-2026-40638 | Dell PowerScale InsightIQ 安全漏洞 — PowerScale InsightIQ | 6.7 | Medium | 2026-05-12 |
| CVE-2026-42088 | OpenC3 COSMOS 安全漏洞 — cosmos | 9.6 | Critical | 2026-05-04 |
| CVE-2026-40550 | BinSoft mpGabinet 安全漏洞 — mpGabinet | 8.8AI | HighAI | 2026-04-28 |
| CVE-2026-25908 | Dell Alienware Command Center 安全漏洞 — Alienware Command Center (AWCC) | 6.7 | Medium | 2026-04-27 |
| CVE-2026-4667 | HP System Optimizer 安全漏洞 — OMEN Gaming Hub | 7.8 | - | 2026-04-15 |
| CVE-2026-33793 | Juniper Networks Junos OS和Juniper Networks Junos OS Evolved 安全漏洞 — Junos OS | 7.8 | High | 2026-04-09 |
| CVE-2026-4498 | Elastic Kibana Fleet 安全漏洞 — Kibana | 7.7 | High | 2026-04-08 |
| CVE-2026-1346 | IBM多款产品 安全漏洞 — Verify Identity Access Container | 9.3 | Critical | 2026-04-08 |
| CVE-2026-4606 | GeoVision GV Edge Recording Manager 安全漏洞 — GV-Edge Recording Manager | 7.8 | - | 2026-03-23 |
| CVE-2025-12690 | Forcepoint NGFW Engine 安全漏洞 — NGFW Engine | 7.8AI | HighAI | 2026-03-11 |
| CVE-2026-20017 | Cisco Secure Firewall Threat Defense 安全漏洞 — Cisco Secure Firewall Threat Defense (FTD) Software | 6.0 | Medium | 2026-03-04 |
| CVE-2026-21424 | Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS | 6.7 | Medium | 2026-03-04 |
| CVE-2026-21421 | Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS | 6.7 | Medium | 2026-03-04 |
| CVE-2026-21426 | Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS | 6.7 | Medium | 2026-03-04 |
| CVE-2026-20037 | Cisco UCS Manager Software 安全漏洞 — Cisco Unified Computing System (Managed) | 4.4 | Medium | 2026-02-25 |
| CVE-2026-27002 | OpenClaw 安全漏洞 — openclaw | 9.6 | - | 2026-02-19 |
| CVE-2025-1790 | Genetec Sipelia Plugin 安全漏洞 — Genetec Sipelia | 7.8AI | HighAI | 2026-02-13 |
| CVE-2026-25740 | Nixpkgs 安全漏洞 — nixpkgs | 8.8AI | HighAI | 2026-02-09 |
| CVE-2026-0870 | GIGABYTE MacroHub 安全漏洞 — MacroHub | 7.8 | High | 2026-02-09 |
| CVE-2025-13375 | IBM Common Cryptographic Architecture 安全漏洞 — Common Cryptographic Architecture | 9.8 | Critical | 2026-02-04 |
| CVE-2026-22549 | F5 BIG-IP Container Ingress Services 安全漏洞 — F5 BIG-IP Container Ingress Services | 4.9 | Medium | 2026-02-04 |
| CVE-2025-58379 | Broadcom Brocade Fabric OS 安全漏洞 — Fabric OS | 5.5AI | MediumAI | 2026-02-03 |
CWE-250(带着不必要的权限执行) 是常见的弱点类别,本平台收录该类弱点关联的 245 条 CVE 漏洞。