CWE-271 · 11 records
Privilege Dropping / Lowering Errors
CVEs in this class
11 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-22648No exploit | A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while theysuse · rancher · CWE-271 | High8.8 | — | 0.5% | Jun 1, 2023 |
33Monitor | CVE-2024-0985No exploit | PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQLpostgresql · postgresql · CWE-271 | High8.0 | — | 1.8% | Feb 8, 2024 |
32Monitor | CVE-2019-11243No exploit | In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials rkubernetes · kubernetes · CWE-271 | High8.1 | — | 1.5% | Apr 22, 2019 |
32Monitor | GHSA-55f6-4pr5-c7m5No exploit | Kahi has privilege-drop and socket/log permission issuesGo · github.com/kahiteam/kahi · CWE-271 | High8.0 | — | — | Jun 30, 2026 |
31Monitor | CVE-2022-3569Weaponized | Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versionsynacor · zimbra collaboration suite · CWE-271 | High7.8 | — | 0.7% | Oct 17, 2022 |
31Monitor | CVE-2026-35535No exploit | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailersudo project · sudo · CWE-271 | High7.8 | — | 0.2% | Apr 2, 2026 |
31Monitor | CVE-2025-53819No exploit | Nix's privilege dropping to build user broke for macOSnixos · nix · CWE-271 | High7.9 | — | 0.1% | Jul 14, 2025 |
29Monitor | CVE-2025-23395No exploit | Local root exploit via `logfile_reopen()` in screen 5.0.0 with setuid-root bit setCWE-271 | High7.3 | — | 0.2% | May 26, 2025 |
27Monitor | CVE-2024-35179No exploit | Unprivileged Stalwart Mail Server user can read files as rootstalwartlabs · mail-server · CWE-271 | Medium6.8 | — | 0.6% | May 15, 2024 |
23Monitor | CVE-2026-25704No exploit | Incomplete privilege drop for com.system76.CosmicGreeter.GetUserDatapop-os · cosmic-greeter · CWE-271 | Medium5.8 | — | 0.1% | Mar 30, 2026 |
19Monitor | CVE-2020-35513No exploit | A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the walinux · linux kernel · CWE-271 | Medium4.9 | — | 1.3% | Jan 26, 2021 |
- CVE-2023-2264835Monitor
A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they
HighCVSS 8.8No exploitEPSS 0%suse · rancherJun 1, 2023
- CVE-2024-098533Monitor
PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL
HighCVSS 8.0No exploitEPSS 2%postgresql · postgresqlFeb 8, 2024
- CVE-2019-1124332Monitor
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials r
HighCVSS 8.1No exploitEPSS 1%kubernetes · kubernetesApr 22, 2019
- GHSA-55f6-4pr5-c7m532Monitor
Kahi has privilege-drop and socket/log permission issues
HighCVSS 8.0No exploitGo · github.com/kahiteam/kahiJun 30, 2026
- CVE-2022-356931Monitor
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in version
HighCVSS 7.8WeaponizedEPSS 1%synacor · zimbra collaboration suiteOct 17, 2022
- CVE-2026-3553531Monitor
In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer
HighCVSS 7.8No exploitEPSS 0%sudo project · sudoApr 2, 2026
- CVE-2025-5381931Monitor
Nix's privilege dropping to build user broke for macOS
HighCVSS 7.9No exploitEPSS 0%nixos · nixJul 14, 2025
- CVE-2025-2339529Monitor
Local root exploit via `logfile_reopen()` in screen 5.0.0 with setuid-root bit set
HighCVSS 7.3No exploitEPSS 0%May 26, 2025
- CVE-2024-3517927Monitor
Unprivileged Stalwart Mail Server user can read files as root
MediumCVSS 6.8No exploitEPSS 1%stalwartlabs · mail-serverMay 15, 2024
- CVE-2026-2570423Monitor
Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData
MediumCVSS 5.8No exploitEPSS 0%pop-os · cosmic-greeterMar 30, 2026
- CVE-2020-3551319Monitor
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the wa
MediumCVSS 4.9No exploitEPSS 1%linux · linux kernelJan 26, 2021