CWE-268Base

Privilege Chaining

Draft in the CWE catalog · 22 CVEs mapped

22
CVEs mapped
7.2
Median CVSS
What it is

Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.

Recent examples
8.5cvss
CVE-2026-32325

Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier

Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.

HIGHno explanation yet
0%
epss
7.8cvss
CVE-2026-3888

Local Privilege Escalation in snapd

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

HIGHno explanation yet
0%
epss
8.5cvss
CVE-2025-64701

QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system…

⚡ A logged-in user could easily escalate their privileges to admin status in QND Premium/Advance/Standard versions up to 11.0.9i — it’s like finding an unguarded back door in your home! 🔥 Think of it as a guest who checks into a hotel but finds a way to access the manager's suite — all because the door was carelessly left unlocked! This vulnerability allows unauthorized access to sensitive information and system controls. An attacker could read, modify, or delete sensitive data, and even execute arbitrary commands! This poses a significant risk to the integrity of your system, potentially resulting in data breaches or unauthorized system changes. Losing control over your system could be absolutely devastating!

HIGH
0%
epss
The record
Technical detail
CWE ID
CWE-268
Abstraction
Base
Structure
Simple
Status
Draft
References (1)