CWE-268 特权链锁 类弱点 20 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-268 特权链漏洞指攻击者通过组合两个或多个独立权限,执行原本被禁止的危险操作。攻击者通常利用系统对权限叠加逻辑的忽视,将低权限能力串联以突破安全边界。开发者应避免权限隐式叠加,实施最小权限原则,并严格审查权限组合逻辑,确保单一权限无法通过组合产生未授权的越权行为,从而阻断攻击路径。
public enum Roles { ADMIN,OPERATOR,USER,GUEST } public void resetPassword(User requestingUser, User user, String password ){ if(isAuthenticated(requestingUser)){ switch(requestingUser.role){ case GUEST: System.out.println("You are not authorized to perform this command"); break; case USER: System.out.println("You are not authorized to perform this command"); break; default: setPassword(user,password); break; } } else{ System.out.println("You must be logged in to perform this command"); } }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-3888 | Canonical Ubuntu Linux 安全漏洞 | 7.8 | High | 2026-03-17 |
| CVE-2025-64701 | QualitySoft QND 安全漏洞 — QND Premium/Advance/Standard | 7.8AI | HighAI | 2025-12-11 |
| CVE-2025-7973 | Rockwell Automation FactoryTalk Viewpoint 安全漏洞 — FactoryTalk® ViewPoint | 7.8AI | HighAI | 2025-08-14 |
| CVE-2025-36124 | IBM WebSphere Application Server Liberty 安全漏洞 — WebSphere Application Server Liberty | 5.9 | Medium | 2025-08-12 |
| CVE-2025-2297 | BeyondTrust Privilege Management for Windows 安全漏洞 — Privilege Management for Windows | 7.8AI | HighAI | 2025-07-28 |
| CVE-2025-49741 | Microsoft Edge 安全漏洞 — Microsoft Edge (Chromium-based) | 7.4 | High | 2025-07-01 |
| CVE-2025-20112 | Cisco Unified Communications 安全漏洞 — Cisco Emergency Responder | 5.1 | Medium | 2025-05-21 |
| CVE-2025-32955 | Harden-Runner 安全漏洞 — harden-runner | 6.0 | Medium | 2025-04-21 |
| CVE-2025-2903 | Google Cloud Platform 安全漏洞 — Delphix | 9.8AI | CriticalAI | 2025-04-17 |
| CVE-2024-4877 | OpenVPN 安全漏洞 — OpenVPN | 7.8AI | HighAI | 2025-04-03 |
| CVE-2025-0889 | BeyondTrust Endpoint Privilege Management for Windows 安全漏洞 — Privilege Management for Windows | 7.0 | - | 2025-02-26 |
| CVE-2024-47045 | e-Tax Reception System 安全漏洞 — The installer of e-Tax software(common program) | 7.8AI | HighAI | 2024-09-26 |
| CVE-2024-1299 | GitLab 安全漏洞 — GitLab | 6.5 | Medium | 2024-03-07 |
| CVE-2024-1250 | GitLab和Git 安全漏洞 — GitLab | 6.5 | Medium | 2024-02-12 |
| CVE-2023-5839 | HestiaCP 安全漏洞 — hestiacp/hestiacp | 8.8 | - | 2023-10-29 |
| CVE-2023-20194 | Cisco Identity Services Engine 安全漏洞 — Cisco Identity Services Engine Software | 4.9 | Medium | 2023-09-07 |
| CVE-2023-2250 | Open Cluster Management 安全漏洞 — MCE | 8.8 | - | 2023-04-24 |
| CVE-2023-0759 | Cockpit 安全漏洞 — cockpit-hq/cockpit | 8.8 | - | 2023-02-09 |
| CVE-2022-1003 | Mattermost 安全漏洞 — Mattermost | 3.3 | Low | 2022-03-18 |
| CVE-2019-3844 | systemd 权限许可和访问控制问题漏洞 — systemd | 7.8 | - | 2019-04-26 |
CWE-268(特权链锁) 是常见的弱点类别,本平台收录该类弱点关联的 20 条 CVE 漏洞。