Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private
Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploit
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows i
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challe
QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to befor
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security rest
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authentica
An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Lo
A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations
Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited,
An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assign
A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration
Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-
A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the syste
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of
Frequently Asked Questions
What is CWE-268?
CWE-268 (CWE-268) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-268?
There are 22 CVE records associated with CWE-268 in our database. Of these, 1 are critical severity, 11 are high severity, and 7 are medium severity.
How can I protect against CWE-268 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-268 using AI-powered security agents.
Detect CWE-268 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-268 vulnerabilities across your infrastructure.
Get Started