Security Risk Category

Privilege Escalation Security Risks — Page 4

Published vulnerability pages connected to Privilege Escalation. Each page keeps one canonical URL and focused remediation guidance.

113 published Privilege Escalation risks

Privilege Escalation risks

Showing 109–113 of 113 published risks.

criticalCISA KEVEPSS 0.846

Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CVE-2026-9082drupalapi-securityremote-code-executionsql-injection

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.963

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

CVE-2026-31431linuxprivilege-escalation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.046

Microsoft Windows Link Following Vulnerability

Microsoft Windows contains a link following vulnerability that allows for privilege escalation

CVE-2025-60710windowsmicrosoftpath-traversalprivilege-escalation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.070

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

CVE-2026-20122network-securityapi-securityfile-writeprivilege-escalation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.053

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

CVE-2026-20128network-securityprivilege-escalation

Updated Jul 9, 2026