CWE-783Base

Operator Precedence Logic Error

Draft in the CWE catalog · 6 CVEs mapped

6
CVEs mapped
7.4
Median CVSS
What it is

The product uses an expression in which operator precedence causes incorrect logic to be used.

Recent examples
7.8cvss
CVE-2026-7270

Local privilege escalation via execve()

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

HIGHno explanation yet
0%
epss
6.9cvss
CVE-2026-0209

Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured

Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured.

MEDIUMno explanation yet
0%
epss
7.1cvss
CVE-2026-25233

PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug

⚡ A logic bug in PEAR lets non-lead maintainers take control of roadmaps! 🚧 Think of this like a restaurant where waitstaff can rewrite the menu without the chef's approval, potentially leading to some questionable dish choices. Just like a rogue waiter could spoil the special of the day, the wrong maintainer could alter project direction. This could allow unauthorized users to create, update, or delete crucial project roadmaps, jeopardizing the integrity and future direction of your application. Imagine someone hijacking the steering wheel while you're on a road trip—chaos is bound to ensue!

HIGH
0%
epss
The record
Technical detail
CWE ID
CWE-783
Abstraction
Base
Structure
Simple
Status
Draft
References (1)