Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-27357MEDIUMAn issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, andEPSS 0.2%CVE-2023-42952MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOEPSS 0.2%CVE-2025-36633HIGHLocal Privilege EscalationEPSS 0.2%CVE-2026-61204CRITICALVulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supEPSS 0.2%CVE-2026-40001MEDIUMLocal privilege escalation vulnerability in ZTE PROCESS Guard service of the cloud computer clientEPSS 0.2%CVE-2026-87273HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-9067HIGHRockwell Automation FactoryTalk® Linx Privilege Escalation VulnerabilitiesEPSS 0.2%CVE-2025-43512HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14EPSS 0.2%CVE-2025-9068HIGHRockwell Automation FactoryTalk® Linx Privilege Escalation VulnerabilitiesEPSS 0.2%CVE-2022-48226HIGHAn issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During installation, an EXE gets executed out of C:\Windows\Temp. A standaEPSS 0.2%CVE-2021-31839MEDIUMIncorrect permissions on McAfee Agent for Windows event folderEPSS 0.2%CVE-2024-44147HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized accessEPSS 0.2%CVE-2024-34332HIGHAn issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a crafted buffer sent tEPSS 0.2%CVE-2026-60406MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.2%CVE-2026-35288HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions EPSS 0.2%CVE-2026-61182MEDIUMVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The suEPSS 0.2%CVE-2025-55581HIGHD-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. EPSS 0.2%CVE-2026-40572CRITICALNovumOS has Arbitrary Memory Mapping via Syscall 15 (MemoryMapRange)EPSS 0.2%CVE-2026-87248MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2024-33224HIGHAn issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privilegEPSS 0.2%