CWE-250Base2 in KEV

Execution with Unnecessary Privileges

Draft in the CWE catalog · 317 CVEs mapped

317
CVEs mapped
2
In KEV
7.8
Median CVSS
What it is

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Recent examples
6.4cvss
CVE-2026-83534

PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel()

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions

MEDIUMno explanation yet
epss
6.5cvss
CVE-2026-72654

CVE-2026-72654 - MEDIUM Severity Vulnerability

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.

MEDIUMno explanation yet
0%
epss
7.8cvss
CVE-2026-30512

CVE-2026-30512 - HIGH Severity Vulnerability

A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlying Windows operating system. An authenticated low-privileged user can escape the kiosk environment by opening the application manual in the external PDF viewer and abusing the print functionality. Successful exploitation allows execution of arbitrary commands outside the kiosk environment with local administrator privileges.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-250
Abstraction
Base
Structure
Simple
Status
Draft
References (8)