CWE-267Base1 in KEV

Privilege Defined With Unsafe Actions

Incomplete in the CWE catalog · 53 CVEs mapped

53
CVEs mapped
1
In KEV
7.3
Median CVSS
What it is

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Recent examples
3.3cvss
CVE-2026-18858

CVE-2026-18858 - LOW Severity Vulnerability

IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.

LOWno explanation yet
0%
epss
3.3cvss
CVE-2026-81161

CVE-2026-81161 - LOW Severity Vulnerability

Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.

LOWno explanation yet
0%
epss
7.5cvss
CVE-2025-36255

CVE-2025-36255 - HIGH Severity Vulnerability

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-267
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)