CWE-272: CWE-272
Yearly Trend
Top Affected Vendors
All CWE-272 CVEs (13)
This CVE describes a privilege escalation vulnerability where the web server binary runs with root privileges, violating the principle of least privil...
Jan 26, 2026The Social Streams WordPress plugin allows authenticated attackers with Subscriber-level access or higher to escalate their privileges to Administrato...
Jul 23, 2025Veritas System Recovery versions before 23.3_Hotfix have insecure folder permissions that allow low-privileged users to modify or access sensitive fil...
May 14, 2024This vulnerability allows local privilege escalation in Wibu CodeMeter installations. An attacker with local unprivileged access can gain SYSTEM/admin...
May 16, 2025This CVE describes a local privilege escalation vulnerability in Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs. Local users can ex...
Mar 22, 2024This vulnerability allows local authenticated users on Brocade Fabric OS systems to escalate their privileges to root level using specific commands. I...
Feb 3, 2026This vulnerability in the mk_informix Checkmk agent plugin allows local users to escalate privileges due to least privilege violations and reliance on...
Aug 20, 2024A privilege escalation vulnerability in Notepad++ installer versions 8.8.1 and earlier allows unprivileged users to gain SYSTEM-level privileges throu...
Jun 23, 2025Dell Display Manager version 2.1.1.17 contains a privilege escalation vulnerability where low-privileged users can execute arbitrary code during insta...
Feb 6, 2024Dell Display Manager versions 2.1.0 and earlier contain a privilege escalation vulnerability during installation. A local attacker with low privileges...
Apr 20, 2023A least privilege violation vulnerability in Omron NJ/NX-series Machine Automation Controllers allows attackers to bypass intended access restrictions...
Jul 14, 2025JetBrains TeamCity versions before 2025.11.1 stored GitHub personal access tokens instead of installation tokens, granting excessive privileges. This ...
Dec 16, 2025Pepr, a type-safe Kubernetes middleware, defaults to cluster-admin RBAC configuration in versions before 1.0.5, granting excessive permissions that vi...
Jan 16, 2026About CWE-272 (CWE-272)
Our database tracks 13 CVEs classified as CWE-272, with 0 rated critical and 11 rated high severity. The average CVSS score for CWE-272 vulnerabilities is 7.2.
External reference: View CWE-272 on MITRE CWE →
Monitor CWE-272 Vulnerabilities
Get alerted when new CWE-272 CVEs affect your infrastructure.
Start Monitoring Free