CWE-250

CWE-250 · 7 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-250, highest CVSS first.

  1. CRITICAL 10CVE-2026-77521public PoC

    MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on,…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-88808public PoC

    A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where …

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.8CVE-2026-92574

    A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and sec…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.1CVE-2026-84787

    ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.8CVE-2026-102247public PoC

    A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack m…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 4.4CVE-2026-19087

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-87899

    Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

    AI risk analysis on Exploit-DB.ai →