Skip to main content

Threats Tagged 'cwe-268'

View all threats tagged with 'cwe-268'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-268

Threats Tagged 'cwe-268'

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-3888 is a local privilege escalation vulnerability in snapd on Linux systems, specifically affecting multiple Ubuntu LTS versions from 16.04 through 24.04. The flaw arises when systemd-tmpfiles is configured to automatically clean snap's private /tmp directory, allowing a local attacker to re-create this directory and escalate privileges to root. The vulnerability has a high severity score of 7.8, reflecting its potential to compromise confidentiality, integrity, and availability. Exploitation requires local access and elevated privileges but no user interaction. No known exploits are currently reported in the wild. Organizations running affected Ubuntu LTS versions with snapd and systemd-tmpfiles configured as described should prioritize patching or mitigating this issue to prevent privilege chaining attacks.

Join the discussion

A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe console window, which runs with SYSTEM privileges. This can be exploited to spawn an elevated command prompt, enabling full privilege escalation.

Join the discussion

IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration

Join the discussion

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.

Join the discussion

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Join the discussion
0

It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-268
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses