← Back
CWE-648

66 CVEs • Abstraction: Base • Likelihood of Exploit: Low

Incorrect Use of Privileged APIs

The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

JSON object

Loading...

CVEs (66)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mongodb
1Ops Manager Server
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner result...Show more
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.Show less
1Cisco
1Secure Workload
Jun 17, 2026
Jun 28, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attack...Show more
A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials. This vulnerability is due to improper role-based access control (RBAC) of certain OpenAPI operations. An attacker could exploit this vulnerability by issuing a crafted OpenAPI function call with valid credentials. A successful exploit could allow the attacker to execute OpenAPI operations that are reserved for the Administrator user, including the creation and deletion of user labels.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Apr 16, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can all...Show more
XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is used for checking rights. The problem has been patched in XWiki 14.10 and 14.4.7 by returning a safe script API.Show less
1Dell
1Powerprotect Data Manager
Jun 17, 2026
Apr 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended acce...Show more
Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and perform unauthorized actions. Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Jan 20, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerab...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control on a feature within the web-based management interface of the affected system. An attacker could exploit this vulnerability by accessing features through direct requests, bypassing checks within the application. A successful exploit could allow the attacker to take privileged actions within the web-based management interface that should be otherwise restricted. {{value}} ["%7b%7bvalue%7d%7d"])}]] Show less
1Usememos
1Memos
Jun 17, 2026
Dec 28, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
1Usememos
1Memos
Jun 17, 2026
Dec 28, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
1Usememos
1Memos
Jun 17, 2026
Dec 23, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
1Cisco
1Identity Services Engine
Jun 17, 2026
Nov 4, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vulnerability. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx"] Show less
1Pingidentity
1Pingid Integration For Windows Login
Jun 17, 2026
Jun 30, 2022
N/A· v4
8.2 HIGH· v3
4.4 MEDIUM· v2
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID...Show more
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, such as those typically used by PingFederate, into PingID Windows Login user endpoints. Using sensitive full permissions properties file outside of a privileged trust boundary leads to an increased risk of exposure or discovery, and an attacker could leverage these credentials to perform administrative actions against PingID APIs or endpoints.Show less
1Trudesk Project
1Trudesk
Jun 17, 2026
Jun 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
1Xwiki
1Xwiki
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.Show less
1Navercorp
1Whale
Jun 17, 2026
Mar 17, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any URL when users access the store.
1Navercorp
1Whale
Jun 17, 2026
Jan 28, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs.
1Mongodb
1Ops Manager
Jun 17, 2026
Nov 23, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and includ...Show more
Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and including 4.2.17, MongoDB Ops Manager v4.3 versions prior to and including 4.3.9 and MongoDB Ops Manager v4.4 versions prior to and including 4.4.2.Show less
4Archlinux
CentosDebian+1 more
4Arch Linux
BubblewrapCentos+1 more
Jun 17, 2026
Mar 31, 2020
N/A· v4
7.8 HIGH· v3
8.5 HIGH· v2
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root whi...Show more
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user namespaces enabled (not default) * Centos 7 flatpak COPR, if unprivileged user namespaces enabled (not default) This has been fixed in the 0.4.1 release, and all affected users should update.Show less
2Artifex
Fedoraproject
2Fedora
Ghostscript
Jun 17, 2026
Nov 27, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted...Show more
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
2Artifex
Redhat
93scale Api Management
Enterprise LinuxEnterprise Linux Desktop+6 more
Jun 17, 2026
Nov 27, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially cra...Show more
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.Show less
3Artifex
FedoraprojectOpensuse
3Fedora
GhostscriptLeap
Jun 17, 2026
Nov 15, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker coul...Show more
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.Show less
5Artifex
DebianFedoraproject+2 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
Jun 17, 2026
Sep 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted Po...Show more
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less