Weaknesses of type CWE-269

2,518 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-20274MEDIUMA vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges onEPSS 0.2%CVE-2025-24307LOWImproper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow aEPSS 0.2%CVE-2026-20607MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS TahoEPSS 0.2%CVE-2026-7977MEDIUMInappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a EPSS 0.2%CVE-2025-62686MEDIUMA local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance InstallatiEPSS 0.2%CVE-2023-7241HIGHWebroot Antivirus COM-Hijacking LPEEPSS 0.2%CVE-2022-23455HIGHPotential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromEPSS 0.2%CVE-2025-27846MEDIUMIn ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOEPSS 0.2%CVE-2022-3369HIGHImproper handling of registry symbolic links in Bitdefender EnginesEPSS 0.2%CVE-2025-27847MEDIUMIn ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.EPSS 0.2%CVE-2022-32931MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to EPSS 0.2%CVE-2022-41975HIGHRealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.EPSS 0.2%CVE-2021-42082HIGHLocal Privilege Escalation to root in OSNEXUS QuantaStor before 6.0.0.355EPSS 0.2%CVE-2024-21807CRITICALImproper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may EPSS 0.2%CVE-2024-25088HIGHImproper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.EPSS 0.2%CVE-2026-12450MEDIUMInappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive infEPSS 0.2%CVE-2024-27357MEDIUMAn issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, andEPSS 0.2%CVE-2024-22106HIGHImproper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cauEPSS 0.2%CVE-2023-0221MEDIUMProduct security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypEPSS 0.2%CVE-2025-36633HIGHLocal Privilege EscalationEPSS 0.2%