Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-12313MEDIUMInformation disclosure, sandbox escape in the Security: Process Sandboxing componentEPSS 0.2%CVE-2026-87183HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2025-33187CRITICALNVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areasEPSS 0.2%CVE-2026-16997HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2023-41138HIGHThe AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user pEPSS 0.2%CVE-2022-36833HIGHImproper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 EPSS 0.2%CVE-2023-44219—A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows aEPSS 0.2%CVE-2026-11296HIGHInappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendeEPSS 0.2%CVE-2021-3439HIGHHP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate tEPSS 0.2%CVE-2024-23764MEDIUMCertain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server SecuriEPSS 0.2%CVE-2026-46877MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affecEPSS 0.2%CVE-2026-49883CRITICALIn checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permissioEPSS 0.2%CVE-2023-5993HIGHPrivilege Escalation in SafeNet Authentication Client InstallerEPSS 0.2%CVE-2023-40155MEDIUMUncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalEPSS 0.2%CVE-2023-35140MEDIUMThe improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated EPSS 0.2%CVE-2025-65621MEDIUMSnipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administratorEPSS 0.2%CVE-2025-36631HIGHLocal Privilege EscalationEPSS 0.2%CVE-2025-37186HIGHLocal Privilege Escalation Vulnerability in HPE Aruba Networking Virtual Intranet Access (VIA) Client for LinuxEPSS 0.2%CVE-2022-3990HIGHHPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customers who opted for autoEPSS 0.2%CVE-2024-9002HIGHCWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and avEPSS 0.2%