CWE-272Base

Least Privilege Violation

Incomplete in the CWE catalog · 37 CVEs mapped

37
CVEs mapped
7.3
Median CVSS
What it is

The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.

Recent examples
6.6cvss
CVE-2025-62299

CVE-2025-62299 - MEDIUM Severity Vulnerability

HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.

MEDIUMno explanation yet
0%
epss
7.3cvss
CVE-2026-59915

CVE-2026-59915 - HIGH Severity Vulnerability

Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

HIGHno explanation yet
0%
epss
6.0cvss
CVE-2026-49500

CVE-2026-49500 - MEDIUM Severity Vulnerability

Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service and Elevation of Privileges.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-272
Abstraction
Base
Structure
Simple
Status
Incomplete
References (2)