CWE-648Base1 in KEV

Incorrect Use of Privileged APIs

Incomplete in the CWE catalog · 63 CVEs mapped

63
CVEs mapped
1
In KEV
7.5
Median CVSS
What it is

The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

Recent examples
8.7cvss
CVE-2026-63727

Anchore Enterprise Privilege Escalation via User Management API

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read only user could be granted write access. This issue is fixed in Anchore Enterprise 5.27.2 and 6.0.1.

HIGHno explanation yet
0%
epss
8.4cvss
CVE-2026-54424

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment variable.

HIGHno explanation yet
0%
epss
6.3cvss
CVE-2026-11877

Missing Authorization Vulnerability in OpenText Access Manager

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-648
Abstraction
Base
Structure
Simple
Status
Incomplete