Common Weakness Enumeration

    CWE Definition / CWE-648

    CWE-648: Incorrect Use of Privileged APIs

    The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

    Published:30 Jan 2008
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-269: Improper Privilege Management