CVSS Scores Are Not Enough: Why Authority Matters in Vulnerability Exploitation
For years, cybersecurity experts have debated the limitations of Common Vulnerability Scoring System (CVSS), which scores vulnerabilities on a scale from 0 to 10. CVSS has been widely used as a metric for prioritizing patching and vulnerability remediation, but it has its drawbacks. According to Kevin E. Greene, public sector chief cybersecurity technologist at BeyondTrust, the score alone does not provide enough information for defenders to make informed decisions about what to patch first.
The problem lies in the fact that CVSS does not capture the privilege state of a vulnerability, which is crucial for determining its operational effectiveness. The entry and exit states of a vulnerability are equally important, as they determine what privileges a threat actor needs to exploit it and what authority they gain if successful.
Greene uses the example of CVE-2026-76460, a bug in Cisco's Identity Service Engine that can result in command execution with root privileges. The CVSS score for this vulnerability is 10, but the privilege state is not accurately represented by the score alone. In fact, the enabling condition for exploitation - the authority transition from a local user to root - is buried in a footnote.
Greene argues that the current system of tracking vulnerabilities has several blind spots, including the lack of structured fields for entry and exit authorities in CVE records. This makes it difficult for defenders to determine what privilege a threat actor needs to start with, what authority they gain after exploitation, and what that authority governs.
The article concludes by stating that what really matters is not the score, but the authority exploitation gives a threat actor - and what that authority allows them to do next. Greene emphasizes that defenders should drop everything and patch when there's a risk of significant privilege escalation, regardless of the CVSS score.