目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-250 带着不必要的权限执行 类漏洞列表 300

CWE-250 带着不必要的权限执行 类弱点 300 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-250指程序以高于实际所需的最小权限级别执行操作。这种过度授权不仅可能直接引发权限提升漏洞,还会放大其他安全缺陷的后果。攻击者常利用此弱点,通过触发特定功能获取更高系统控制权,从而执行恶意代码或窃取敏感数据。开发者应遵循最小权限原则,在代码中严格限制进程权限,确保仅授予完成任务所必需的最低特权,从而降低潜在安全风险。

MITRE CWE 官方描述
CWE:CWE-250 Execution with Unnecessary Privileges 英文:The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
常见影响 (1)
Confidentiality, Integrity, Availability, Access Control Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands, Read Application Data, DoS: Crash, Exit, or Restart
An attacker will be able to gain access to any resources that are allowed by the extra privileges. Common results include executing code, disabling services, and reading restricted data. New weaknesses can be exposed because running with extra privileges, such as root or Administrator, can disable t…
缓解措施 (5)
Architecture and Design, Operation Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database ad…
Architecture and Design Identify the functionality that requires additional privileges, such as access to privileged operating system resources. Wrap and centralize this functionality if possible, and isolate the privileged code as much as possible from other code [REF-76]. Raise privileges as late as possible, and drop them as soon as possible to avoid CWE-271. Avoid weaknesses such as CWE-288 and CWE-420 by protecting …
Architecture and Design Identify the functionality that requires additional privileges, such as access to privileged operating system resources. Wrap and centralize this functionality if possible, and isolate the privileged code as much as possible from other code [REF-76]. Raise privileges as late as possible, and drop them as soon as possible to avoid CWE-271. Avoid weaknesses such as CWE-288 and CWE-420 by protecting …
Implementation Perform extensive input validation for any privileged code that must be exposed to the user and reject anything that does not fit your strict requirements.
Implementation When dropping privileges, ensure that they have been dropped successfully to avoid CWE-273. As protection mechanisms in the environment get stronger, privilege-dropping calls may fail even if it seems like they would always succeed.
代码示例 (2)
This code temporarily raises the program's privileges to allow creation of a new user folder.
def makeNewUserDir(username): if invalidUsername(username): #avoid CWE-22 and CWE-78 print('Usernames cannot contain invalid characters') return False try: raisePrivileges() os.mkdir('/home/' + username) lowerPrivileges() except OSError: print('Unable to create new user directory for user:' + username) return False return True
Bad · Python
The following code calls chroot() to restrict the application to a subset of the filesystem below APP_HOME in order to prevent an attacker from using the program to gain unauthorized access to files located elsewhere. The code then opens a file specified by the user and processes the contents of the file.
chroot(APP_HOME); chdir("/"); FILE* data = fopen(argv[1], "r+"); ...
Bad · C
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-107176 OpenShift Cluster-samples-operator 越权读取配置命名空间所有密钥漏洞 — Red Hat OpenShift Container Platform 4 6.8 Medium 2026-10-07
CVE-2026-106378 Chrome Mac 权限提升漏洞(<155.0.8059.39) — Chrome - - 2026-10-06
CVE-2026-66246 HCL iControl 多个安全漏洞 — iControl 8.8 High 2026-10-01
CVE-2026-53605 Reachy Mini 无线版本地提权漏洞 — reachy-mini-os 7.8 High 2026-09-30
CVE-2026-102247 FastAdmin 数据库管理组件数据库配置文件多余权限漏洞 — FastAdmin 6.8 Medium 2026-09-29
CVE-2026-88808 Fleet Agent 集群管理员权限滥用导致跨命名空间写入漏洞 — Rancher 8.8 High 2026-09-28
CVE-2026-87899 cPanel提权漏洞:远程用户可获Root权限执行代码 — cPanel 9.4 Critical 2026-09-23
CVE-2026-19087 IBM FTM 多漏洞 — Financial Transaction Manager (FTM) for RedHat OpenShift 4.4 Medium 2026-09-23
CVE-2026-84787 权限提升漏洞 — ManageEngine OpManager 8.1 High 2026-09-23
CVE-2026-92574 Cri-o 检查点恢复绕过安全上下文 8.8 High 2026-09-21
CVE-2026-75092 Leapp 9to10 插件加载权限漏洞 — Red Hat Enterprise Linux 9 7.3 High 2026-09-15
CVE-2026-89259 Gohugoio Hugo 权限许可和访问控制问题漏洞 — hugo 9.8 Critical 2026-09-11
CVE-2026-79942 Dell Secure Connect Gateway 权限许可和访问控制问题漏洞 — Secure Connect Gateway 5.0 - Application 3.4 Low 2026-09-09
CVE-2026-87506 Google Chrome 权限许可和访问控制问题漏洞 — Chrome - - 2026-09-09
CVE-2026-69464 Microsoft Office Sharepoint Server 权限许可和访问控制问题漏洞 — Microsoft SharePoint Server Subscription Edition 8.8 High 2026-09-08
CVE-2026-69409 Microsoft Office Sharepoint Server 权限许可和访问控制问题漏洞 — Microsoft SharePoint Server Subscription Edition 6.5 Medium 2026-09-08
CVE-2026-80238 Dell Secure Connect Gateway 权限许可和访问控制问题漏洞 — Secure Connect Gateway 5.0 - Application 9.3 Critical 2026-09-07
CVE-2026-83534 DALIBO postgresql anonymizer 权限许可和访问控制问题漏洞 — PostgreSQL Anonymizer 6.4 Medium 2026-09-06
CVE-2026-72654 Elastic kibana 权限许可和访问控制问题漏洞 — Kibana 6.5 Medium 2026-09-01
CVE-2026-76018 Google Chrome 权限许可和访问控制问题漏洞 — Chrome - - 2026-08-20
CVE-2026-70496 Stolostron search-v2-operator 权限许可和访问控制问题漏洞 — Red Hat Advanced Cluster Management for Kubernetes 2.11 9.9 Critical 2026-08-19
CVE-2026-24183 NVIDIA Cumulus Linux GA 权限许可和访问控制问题漏洞 — Cumulus Linux GA 7.8 High 2026-08-18
CVE-2026-71846 Red Hat Insights Client 权限许可和访问控制问题漏洞 — Red Hat Advanced Cluster Management for Kubernetes 2.11 6.5 Medium 2026-08-12
CVE-2026-72508 Red Hat Advanced Cluster Management for Kubernetes 权限许可和访问控制问题漏洞 — Red Hat Advanced Cluster Management for Kubernetes 2.11 9.9 Critical 2026-08-12
CVE-2026-17445 IBM i 权限许可和访问控制问题漏洞 — i 8.2 High 2026-08-12
CVE-2026-18669 IBM i 权限许可和访问控制问题漏洞 — i 8.8 High 2026-08-12
CVE-2026-17110 IBM i 权限许可和访问控制问题漏洞 — i 8.8 High 2026-08-12
CVE-2026-59133 Microsoft HPC Pack 权限许可和访问控制问题漏洞 — Microsoft HPC Pack 2019 8.8 High 2026-08-11
CVE-2026-18982 Red Hat OpenShift AI 权限许可和访问控制问题漏洞 — Red Hat OpenShift AI 2.25 8.8 High 2026-08-10
CVE-2026-18949 opendatahub open data hub dashboard 权限许可和访问控制问题漏洞 — Red Hat OpenShift AI 2.25 8.8 High 2026-08-10

CWE-250(带着不必要的权限执行) 是常见的弱点类别,本平台收录该类弱点关联的 300 条 CVE 漏洞。