Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-250 (带着不必要的权限执行) — Vulnerability Class 280

280 vulnerabilities classified as CWE-250 (带着不必要的权限执行). AI Chinese analysis included.

CWE-250 represents a critical architectural weakness where software executes operations using elevated privileges beyond what is strictly necessary for the task. This misconfiguration typically allows attackers to exploit other vulnerabilities, such as buffer overflows or injection flaws, by granting them higher-level access than intended. If an attacker compromises a low-privilege component, the excessive permissions amplify the impact, potentially leading to full system compromise or unauthorized data modification. To mitigate this risk, developers must adhere to the principle of least privilege, ensuring that each process or user account operates with only the minimum permissions required for its specific function. Implementing strict access controls, regularly auditing permission assignments, and isolating services further reduce the attack surface, thereby limiting the potential damage from any single security breach.

MITRE CWE Description
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Common Consequences (1)
Confidentiality, Integrity, Availability, Access Control Gain Privileges or Assume Identity, Execute Unauthorized Code or Commands, Read Application Data, DoS: Crash, Exit, or Restart
An attacker will be able to gain access to any resources that are allowed by the extra privileges. Common results include executing code, disabling services, and reading restricted data. New weaknesses can be exposed because running with extra privileges, such as root or Administrator, can disable t…
Mitigations (5)
Architecture and Design, Operation Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database ad…
Architecture and Design Identify the functionality that requires additional privileges, such as access to privileged operating system resources. Wrap and centralize this functionality if possible, and isolate the privileged code as much as possible from other code [REF-76]. Raise privileges as late as possible, and drop them as soon as possible to avoid CWE-271. Avoid weaknesses such as CWE-288 and CWE-420 by protecting …
Architecture and Design Identify the functionality that requires additional privileges, such as access to privileged operating system resources. Wrap and centralize this functionality if possible, and isolate the privileged code as much as possible from other code [REF-76]. Raise privileges as late as possible, and drop them as soon as possible to avoid CWE-271. Avoid weaknesses such as CWE-288 and CWE-420 by protecting …
Implementation Perform extensive input validation for any privileged code that must be exposed to the user and reject anything that does not fit your strict requirements.
Implementation When dropping privileges, ensure that they have been dropped successfully to avoid CWE-273. As protection mechanisms in the environment get stronger, privilege-dropping calls may fail even if it seems like they would always succeed.
Examples (2)
This code temporarily raises the program's privileges to allow creation of a new user folder.
def makeNewUserDir(username): if invalidUsername(username): #avoid CWE-22 and CWE-78 print('Usernames cannot contain invalid characters') return False try: raisePrivileges() os.mkdir('/home/' + username) lowerPrivileges() except OSError: print('Unable to create new user directory for user:' + username) return False return True
Bad · Python
The following code calls chroot() to restrict the application to a subset of the filesystem below APP_HOME in order to prevent an attacker from using the program to gain unauthorized access to files located elsewhere. The code then opens a file specified by the user and processes the contents of the file.
chroot(APP_HOME); chdir("/"); FILE* data = fopen(argv[1], "r+"); ...
Bad · C
CVE ID Title CVSS Severity Published
CVE-2026-46617 Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read — fission - - 2026-06-10
CVE-2026-46748 Siemens SINEC INS 安全漏洞 — SINEC INS 8.8 High 2026-06-09
CVE-2026-10843 Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws — Red Hat OpenShift Container Platform 4 7.2 High 2026-06-04
CVE-2025-12694 Local Privilege Escalation in VPN Client — VPN Client - - 2026-06-04
CVE-2026-42061 Acronis DeviceLock DLP 安全漏洞 — Acronis DeviceLock DLP - - 2026-06-03
CVE-2026-44477 CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE — cloudnative-pg - - 2026-05-28
CVE-2026-3623 Vulnerabilities exists in IBM Netezza Performance Server Replication Services — Netezza Performance Server Replication Services 7.8 High 2026-05-27
CVE-2026-8370 Automic Automation Agent Unix privilege escalation — Automic Automation - - 2026-05-19
CVE-2026-29205 cPanel 安全漏洞 — cPanel 8.6 High 2026-05-13
CVE-2026-32643 BIG-IP and BIG-IQ privilege escalation vulnerability — BIG-IP 6.5 Medium 2026-05-13
CVE-2026-32673 BIG-IP scripted monitor vulnerability — BIG-IP 8.7 High 2026-05-13
CVE-2026-25710 Plasma Workspace 安全漏洞 — plasma-login-manager - - 2026-05-13
CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.1 9.1 Critical 2026-05-12
CVE-2026-40638 Dell PowerScale InsightIQ 安全漏洞 — PowerScale InsightIQ 6.7 Medium 2026-05-12
CVE-2026-42088 OpenC3 COSMOS: Administrative Actions via the Script Runner Tool — cosmos 9.6 Critical 2026-05-04
CVE-2026-40550 Privilege Escalation in mpGabinet — mpGabinet 8.8AI High AI 2026-04-28
CVE-2026-25908 Dell Alienware Command Center 安全漏洞 — Alienware Command Center (AWCC) 6.7 Medium 2026-04-27
CVE-2026-4667 HP System Optimizer - Escalation of Privilege — OMEN Gaming Hub 7.8 - 2026-04-15
CVE-2026-33793 Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system — Junos OS 7.8 High 2026-04-09
CVE-2026-4498 Execution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scope — Kibana 7.7 High 2026-04-08
CVE-2026-1346 Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Verify Identity Access Container 9.3 Critical 2026-04-08
CVE-2026-4606 GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege — GV-Edge Recording Manager 7.8 - 2026-03-23
CVE-2025-12690 Local Privilege Escalation in NGFW Engine — NGFW Engine 7.8AI High AI 2026-03-11
CVE-2026-20017 Cisco Secure FTD Software Authenticated Command Injection Vulnerability — Cisco Secure Firewall Threat Defense (FTD) Software 6.0 Medium 2026-03-04
CVE-2026-21424 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS 6.7 Medium 2026-03-04
CVE-2026-21421 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS 6.7 Medium 2026-03-04
CVE-2026-21426 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS 6.7 Medium 2026-03-04
CVE-2026-20037 Cisco UCS Manager File Write Vulnerability — Cisco Unified Computing System (Managed) 4.4 Medium 2026-02-25
CVE-2026-27002 OpenClaw: Docker container escape via unvalidated bind mount config injection — openclaw 9.6 - 2026-02-19
CVE-2025-1790 Genetec Sipelia Plugin 安全漏洞 — Genetec Sipelia 7.8AI High AI 2026-02-13

Vulnerabilities classified as CWE-250 (带着不必要的权限执行) represent 280 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.