Threats Tagged 'cwe-250'
View all threats tagged with 'cwe-250'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-250'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-48098: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in 0x5t4l1n NexTOR_IP_CHANGERCVE-2026-48098 0 NexTOR_IP_CHANGER versions prior to 2.0.0 contain an OS command injection vulnerability due to improper neutralization of special elements in system commands executed with sudo and shell=True. This allows execution of privileged commands without explicit user confirmation in environments with passwordless sudo enabled. The issue is fixed in version 2.0.0. Join the discussion | CVE Database V5 | 08/07/2026, 19:09:29 UTC Added: 08/07/2026, 21:27:02 UTC |
CVE-2026-50737: CWE-250 Execution with Unnecessary Privileges in EnterpriseDB pglogicalCVE-2026-50737 0 When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply worker runs at a privilege level equivalent to a PostgreSQL superuser in default installations, any function invoked by such a default expression also runs at that privilege. A party acting as the publisher can use this path to cause functions to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser. This is a second, independent path to the same superuser escalation tracked under CVE-2026-50736 (the pglogical queue issue). To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles. Join the discussion | CVE Database V5 | 07/28/2026, 17:55:43 UTC Added: 07/28/2026, 18:22:45 UTC |
CVE-2026-14172: CWE-250 Execution with Unnecessary Privileges in Rapid7 InsightVMCVE-2026-14172 0 Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0. Join the discussion | CVE Database V5 | 07/24/2026, 05:51:14 UTC Added: 07/24/2026, 06:38:42 UTC |
CVE-2026-14985: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Analog Way Picturall Quad Compact Mark IICVE-2026-14985 0 Overview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Quad Compact Mark II is a compact, heavy-duty 8K media server developed by Analog Way for video playback and content management in professional audiovisual environments. The core firmware includes a maintenance script called create_local_installer.sh , and the default script permission allows the low-privileged user, picmedia , to execute it as root and without a password. An attacker creates a malicious Ext4 disk image that contains the file, picturall-version.txt , with a directory traversal string and a payload file. create_local_installer.sh reads input from picturall-version.txt when processing these attacker-supplied disk images. This input is not properly sanitized, allowing an attacker to supply directory traversal sequences. As a result, the attacker can manipulate the script to write files outside of the intended extraction directory and execute a malicious payload. Because the script executes with root privileges, this behavior enables arbitrary file writes to sensitive system locations such as `/etc/cron.d, a system directory in Unix/Linux operating system used to store system-wide task scheduling files. An attacker can then leverage this capability to execute arbitrary code with root privileges. Impact By exploiting this path traversal vulnerability, an attacker with local access to the device can write arbitrary files to privileged locations. This access allows modification of scheduled tasks, and system configuration files. It can also allow the execution of a[RM2.1][MB2.2]rbitrary commands with full system privileges. An attacker does not need valid root credentials to enable straightforward and repeatable exploitation, resulting in complete system compromise.[RM3.1][MB3.2] This constitutes a Technical Impact = Total under the SSVC framework, meaning: The vulnerability gives the adversary total control over the behavior of the software or total disclosure of all information on the affected system. Solution Analog Way has released version 3.5.9 to address this vulnerability. Users are strongly encouraged to update to the fixed release as soon as possible. Acknowledgements Thanks to the reporter James Tully for responsibly disclosing this issue. This document was written by Michael Bragg. Vendor Information One or more vendors are listed for this advisory. Please reference the full report for more information. Other Information CVE IDs: CVE-2026-14985 Date Public: 2026-07-22 Date First Published: 2026-07-22 Date Last Updated: 2026-07-22 14:30 UTC Document Revision: 1 About vulnerability notes Contact us about this vulnerability Provide a vendor statement Join the discussion | CVE Database V5 | 07/22/2026, 14:32:31 UTC Added: 07/22/2026, 14:52:44 UTC |
CVE-2026-8933: CWE-250 Execution with unnecessary privilegesCVE-2026-8933 0 A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority. Join the discussion | GCVE Database | 07/21/2026, 14:02:19 UTC Added: 07/21/2026, 20:06:37 UTC |
CVE-2026-8933: CWE-250 Execution with unnecessary privilegesCVE-2026-8933 0 CVE-2026-8933 is a local privilege escalation vulnerability in snap-confine, a core component used by Canonical snapd to create secure execution environments for snap applications. The flaw affects versions of snap-confine configured with set-capabilities rather than set-uid-root. An unprivileged local attacker can exploit this vulnerability to bypass security restrictions and execute arbitrary code with full root privileges. The vulnerability has a high severity score of 7.8 and impacts version 2.75.0. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 07/21/2026, 14:02:19 UTC Added: 07/21/2026, 14:42:54 UTC |
CVE-2026-15226: CWE-250 Execution with unnecessary privilegesCVE-2026-15226 0 CVE-2026-15226 is a high-severity vulnerability in Canonical snapd's snap-confine component that allows sandbox confinement bypass. The issue arises because the seccomp security templates do not block operations that create or manipulate set-user-ID (setuid) executables. This enables a confined snap application to compile or drop binaries with setuid attributes, potentially allowing privilege escalation within the container namespace. The vulnerability has been addressed by hardening the seccomp template engine to block such actions. Versions prior to 2.76.1 are affected. Join the discussion | CVE Database V5 | 07/21/2026, 14:02:04 UTC Added: 07/21/2026, 14:42:53 UTC |
CVE-2026-13104: CWE-250: Execution with Unnecessary Privileges in Lenovo App StoreCVE-2026-13104 0 A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges. Join the discussion | CVE Database V5 | 07/16/2026, 16:49:06 UTC Added: 07/16/2026, 17:04:11 UTC |
CVE-2026-42486: CWE-250 Execution with unnecessary privileges in Xen XAPICVE-2026-42486 0 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not. * CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write. Join the discussion | CVE Database V5 | 07/09/2026, 15:16:34 UTC Added: 07/09/2026, 15:33:28 UTC |
CVE-2026-23562: CWE-250 Execution with unnecessary privileges in Xen XAPICVE-2026-23562 0 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not. * CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write. Join the discussion | CVE Database V5 | 07/09/2026, 15:15:24 UTC Added: 07/09/2026, 15:33:28 UTC |
Showing 1 to 10 of 13 results