Privilege Escalation
Gaining higher access than originally granted, by exploiting misconfigurations, vulnerabilities, or over-permissioned identities. Tightly linked to privileged access risk.
Most real escalations are not exploits, they are configuration: a group that grants more than anyone realized, a role that can modify its own policy, a certificate template with dangerous permissions, or a service account with domain rights. That is why attack-path analysis across the identity graph finds more than vulnerability scanning does, and why the fix is usually a permission change rather than a patch.
See also: lateral movement, least privilege, what is PAM, identity CVE catalog
Related on Start with Identity
- GlossaryZero Standing Privileges
An access model where no one holds permanent elevated rights; privileges are granted just in time and expire automatically. The strongest form of least privileg
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a
- CVEBeyondTrust PRA and Remote Support unauthenticated command injection
Privileged Remote Access and Remote Support accepted a malicious client request and ran OS commands as the site user. Unauthenticated. CVSS 9.8. CISA KEV. A PAM
- GlossaryBreak-Glass Account
A tightly controlled emergency account used only when normal access fails, with strong vaulting, monitoring, and alerting. Tested regularly so it works in a rea
- GlossaryCIEM
Cloud Infrastructure Entitlement Management. Tools that discover and right-size identities and permissions across AWS, Azure, and GCP, reducing excessive and un
- BlogPalo Alto Networks closes its 25 billion dollar CyberArk acquisition
The largest deal in security industry history closed on 11 February 2026. CyberArk shareholders took 45 dollars cash plus 2.2005 Palo Alto shares per ordinary s