Skip to main content

Threats Tagged 'cwe-250'

View all threats tagged with 'cwe-250'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-250

Threats Tagged 'cwe-250'

Click on any threat for detailed analysis and mitigation recommendations

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_SANDBOX disabled run commands directly as the application user, while the official root container's string-based gosu wrapper allowed shell metacharacters to execute outside the intended sandbox. This issue is fixed in version 2.10.5-lts.

Join the discussion

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8.

Join the discussion

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.

Join the discussion

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Join the discussion

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Join the discussion

Dell Secure Connect Gateway (SCG) 5.0 versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application) contain a critical vulnerability allowing execution with unnecessary privileges. An unauthenticated local attacker with SSH access can exploit the exposed Docker socket to gain root-level access without a password. Additionally, compromising a service inside the orchestrator container enables container escape and host-level control. Dell recommends upgrading to fixed versions to mitigate this risk.

Join the discussion

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.

Join the discussion

CVE-2026-70496 is a critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2.11 affecting the search-v2-operator. The operator's ClusterRole is assigned excessive privileges equivalent to a cluster administrator, enabling it to impersonate other entities, modify RBAC configurations, approve CSRs, and manage ManifestWork. This over-privileging can lead to privilege escalation within the Kubernetes cluster. Red Hat has issued security advisories recommending updates to later versions that address this and other vulnerabilities. No known exploits are reported in the wild at this time.

Join the discussion

NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.

Join the discussion

CVE-2026-71846 is a moderate severity vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2.11. The insights-client component's ServiceAccount is granted cluster-wide read permissions on all Secrets, although it only requires access to a single specific Secret. This excessive privilege could allow an attacker who compromises the insights-client pod or its ServiceAccount token to read all Secrets across the hub cluster, including sensitive credentials such as managed-cluster kubeconfigs.

Join the discussion

Showing 1 to 10 of 144 results

Filters:Tag: cwe-250
Page 1 of 15
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses