CWE-250
CWE-250 · 7 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-250, highest CVSS first.
- CRITICAL 10CVE-2026-77521public PoC
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on,…
- HIGH 8.8CVE-2026-88808public PoC
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where …
- HIGH 8.8CVE-2026-92574
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and sec…
- HIGH 8.1CVE-2026-84787
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
- MEDIUM 6.8CVE-2026-102247public PoC
A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack m…
- MEDIUM 4.4CVE-2026-19087
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
- UNSCOREDCVE-2026-87899
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.