Threats Tagged 'cwe-268'
View all threats tagged with 'cwe-268'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-268'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-3888 is a local privilege escalation vulnerability in snapd on Linux systems, specifically affecting multiple Ubuntu LTS versions from 16.04 through 24.04. The flaw arises when systemd-tmpfiles is configured to automatically clean snap's private /tmp directory, allowing a local attacker to re-create this directory and escalate privileges to root. The vulnerability has a high severity score of 7.8, reflecting its potential to compromise confidentiality, integrity, and availability. Exploitation requires local access and elevated privileges but no user interaction. No known exploits are currently reported in the wild. Organizations running affected Ubuntu LTS versions with snapd and systemd-tmpfiles configured as described should prioritize patching or mitigating this issue to prevent privilege chaining attacks. Join the discussion | CVE Database V5 | 03/17/2026, 14:02:08 UTC Added: 03/17/2026, 14:13:22 UTC |
0 A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe console window, which runs with SYSTEM privileges. This can be exploited to spawn an elevated command prompt, enabling full privilege escalation. Join the discussion | CVE Database V5 | 08/14/2025, 13:52:53 UTC Added: 08/14/2025, 14:02:49 UTC |
0 IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration Join the discussion | CVE Database V5 | 08/12/2025, 18:45:24 UTC Added: 08/12/2025, 19:02:59 UTC |
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator. Join the discussion | CVE Database V5 | 07/28/2025, 15:40:14 UTC Added: 07/28/2025, 15:47:38 UTC |
0 No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 07/01/2025, 22:22:07 UTC Added: 07/01/2025, 22:39:30 UTC |
0 It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled. Join the discussion | CVE Database V5 | 04/26/2019, 20:26:53 UTC Added: 06/10/2025, 18:54:21 UTC |
Showing 1 to 6 of 6 results