CWE-267: CWE-267

28
Total CVEs
1
Critical
17
High
7.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
4
2025
14
2024
6
2023
4

Top Affected Vendors

1 Oracle 8
2 Ivanti 3
3 Apache 2
4 Hitachienergy 1
5 Asterisk 1
6 Dell 1
7 Siemens 1
8 Pimcore 1
9 Debian 1
10 Cvat 1

All CWE-267 CVEs (28)

CVE-2023-22647
9.9

This CVE-2023-22647 vulnerability in SUSE Rancher allows standard users with existing permissions to manipulate Kubernetes secrets in the local cluste...

Jun 1, 2023
CVE-2026-23526
8.8

CVAT users with staff status can escalate their own privileges to superuser/admin level, gaining full access to all data in the CVAT instance. This af...

Jan 21, 2026
CVE-2025-26467
8.8

This CVE describes a privilege escalation vulnerability in Apache Cassandra where a user with MODIFY permission on all keyspaces can gain superuser pr...

Aug 25, 2025
CVE-2025-23015
8.8

This vulnerability allows users with MODIFY permission on all keyspaces in Apache Cassandra to escalate privileges to superuser by performing unsafe a...

Feb 4, 2025
CVE-2024-55968
EPSS 10.7% 8.8

This vulnerability allows unauthorized local attackers to escalate privileges to root on macOS systems running DTEX DEC-M (DTEX Forwarder) 6.1.1. The ...

Jan 28, 2025
CVE-2024-39866
8.8

This vulnerability in SINEMA Remote Connect Server allows attackers with access to the backup encryption key and upload permissions to create administ...

Jul 9, 2024
CVE-2023-44218
8.8

This vulnerability allows an unauthorized user to exploit SonicWall NetExtender's Pre-Logon feature to gain SYSTEM-level privileges on Windows hosts, ...

Oct 3, 2023
CVE-2023-2983
8.8

This vulnerability in Pimcore allows attackers to perform unsafe actions due to improperly defined privileges, potentially leading to privilege escala...

May 30, 2023
CVE-2025-62588
8.2

A high-severity vulnerability in Oracle VM VirtualBox Core allows attackers with local system access to compromise the virtualization software, potent...

Oct 21, 2025
CVE-2025-62589
8.2

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to completely compromise the Virtual...

Oct 21, 2025
CVE-2025-62641
8.2

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to completely compromise the Virtual...

Oct 21, 2025
CVE-2026-2459
8.1

An authenticated user with Installer role in REB500 can access and modify directories they are not authorized to access. This privilege escalation vul...

Feb 24, 2026
CVE-2025-41244
KEV 7.8

This CVE describes a local privilege escalation vulnerability in VMware Aria Operations and VMware Tools. A malicious local user with non-administrati...

Sep 29, 2025
CVE-2024-7571
7.8

This vulnerability in Ivanti Secure Access Client allows a local authenticated attacker to escalate privileges due to incorrect file permissions. It a...

Nov 12, 2024
CVE-2024-47906
7.8

This vulnerability allows local authenticated attackers to escalate privileges on Ivanti Connect Secure and Policy Secure appliances. Attackers with e...

Nov 12, 2024
CVE-2023-32457
7.5

Dell PowerScale OneFS versions 8.2.2.x through 9.5.0.x contain an improper privilege management vulnerability. A remote attacker with low privileges c...

Aug 29, 2023
CVE-2024-42365
7.4

This vulnerability allows authenticated Asterisk Manager Interface (AMI) users with 'write=originate' permissions to modify configuration files in /et...

Aug 8, 2024
CVE-2024-9842
7.3

This vulnerability in Ivanti Secure Access Client allows local authenticated attackers to create arbitrary folders due to incorrect permissions. This ...

Nov 12, 2024
CVE-2024-20411
6.7

This vulnerability in Cisco NX-OS Software allows authenticated local attackers with Bash shell access to execute arbitrary code with root privileges....

Aug 28, 2024
CVE-2025-53900
6.5

CVE-2025-53900 is a privilege escalation vulnerability in Kiteworks MFT where authorized users can gain elevated permissions through improper role def...

Nov 29, 2025
CVE-2025-61754
6.5

This vulnerability in Oracle BI Publisher allows authenticated attackers with low privileges to access sensitive data via the Web Service API. It affe...

Oct 21, 2025
CVE-2025-62591
6.0

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to access sensitive data from Virtua...

Oct 21, 2025
CVE-2025-53070
5.5

A local privilege escalation vulnerability in Oracle Solaris 11 filesystem component allows high-privileged attackers with system access to cause deni...

Oct 21, 2025
CVE-2026-0945
5.4

A privilege escalation vulnerability in Drupal's Role Delegation module allows authenticated users with role assignment permissions to assign themselv...

Feb 4, 2026
CVE-2025-13979
5.4

This vulnerability in Drupal Mini site allows attackers with certain privileges to inject malicious scripts that execute when other users view affecte...

Jan 28, 2026
CVE-2025-62288
4.9

This vulnerability in Oracle Health Sciences Data Management Workbench allows authenticated high-privilege attackers to access sensitive data via HTTP...

Oct 21, 2025
CVE-2025-62289
4.9

This vulnerability in Oracle ZFS Storage Appliance Kit allows high-privileged attackers with network access via HTTP to cause a denial of service by h...

Oct 21, 2025
CVE-2025-47811
4.1

Wing FTP Server versions through 7.4.4 run the administrative web interface with root/SYSTEM privileges by default. This allows authenticated administ...

Jul 10, 2025

About CWE-267 (CWE-267)

Our database tracks 28 CVEs classified as CWE-267, with 1 rated critical and 17 rated high severity. The average CVSS score for CWE-267 vulnerabilities is 7.3.

External reference: View CWE-267 on MITRE CWE →

Monitor CWE-267 Vulnerabilities

Get alerted when new CWE-267 CVEs affect your infrastructure.

Start Monitoring Free