Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-5671—HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software updates to mitigate EPSS 0.2%CVE-2026-18759HIGHAn improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.EPSS 0.2%CVE-2024-4018HIGHPrivilege Escalation in U-Series ApplianceEPSS 0.2%CVE-2024-4017HIGHPrivilege Escalation in U-Series ApplianceEPSS 0.2%CVE-2024-52926MEDIUMDelinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.EPSS 0.2%CVE-2022-48227HIGHAn issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the instEPSS 0.2%CVE-2026-30892NONECrun incorrectly parses `crun exec` option `-u`, leading to privilege escalationEPSS 0.2%CVE-2023-32490MEDIUM Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentiallyEPSS 0.2%CVE-2022-45853MEDIUMThe privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHIEPSS 0.2%CVE-2023-32487HIGH Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentiallyEPSS 0.2%CVE-2023-5739HIGHCertain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.EPSS 0.2%CVE-2025-62625MEDIUMImproper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentiaEPSS 0.2%CVE-2023-31432HIGHPrivilege issues in multiple commandsEPSS 0.2%CVE-2026-6423HIGHLocal privilege escalation via unauthenticated ALPC in ESET Inspect ConnectorEPSS 0.2%CVE-2023-51386HIGHSandbox Accounts for Events vulnerable to privilege escalation to read running events dataEPSS 0.2%CVE-2023-21896HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. DEPSS 0.2%CVE-2024-21059HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. DifficulEPSS 0.2%CVE-2026-45176HIGHIdira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation ManipulationEPSS 0.2%CVE-2025-54595HIGHPearcleaner's unauthenticated access to privileged XPC helper allows root command executionEPSS 0.2%CVE-2026-90894HIGHParallels Desktop local privilege escalation via appliance extract argument injectionEPSS 0.2%