CWE-270: Privilege Context Switching Error

low-risk

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Abstraction: Base

Common Consequences

Access Control Gain Privileges or Assume Identity

Real-World Examples (10)

CVE CVSS EPSS KEV
CVE-2021-3493 8.8 76.4% Y
CVE-2023-26475 9.9 34.7%
CVE-2023-37912 9.9 9.9%
CVE-2025-49581 8.8 3.9%
CVE-2019-14819 8.8 0.3%
CVE-2023-25754 9.8 0.3%
CVE-2024-36513 8.2 0.2%
CVE-2024-11263 9.3 0.2%
CVE-2024-51987 5.4 0.1%
CVE-2017-2663 8.2 0.1%
5
/ 100
low-risk
Active Threat 4/50 · Minimal
Exploit Availability 1/50 · Minimal