Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2022-37019MEDIUMHP PC BIOS May 2024 Security Updates for Potential Stack Buffer OverflowsEPSS 0.2%CVE-2026-2914HIGHCyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elEPSS 0.2%CVE-2024-20282MEDIUMA vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privilegEPSS 0.2%CVE-2023-30989HIGHIBM i privilege escalationEPSS 0.2%CVE-2026-73974MEDIUMlinuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)EPSS 0.2%CVE-2023-30988HIGHIBM i privilege escalationEPSS 0.2%CVE-2023-38721HIGHIBM i privilege escalationEPSS 0.2%CVE-2026-15380MEDIUMLocal privilege escalation in Symantec ITMSEPSS 0.2%CVE-2026-90894HIGHParallels Desktop local privilege escalation via appliance extract argument injectionEPSS 0.2%CVE-2022-41700MEDIUMInsecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticatEPSS 0.2%CVE-2025-64507HIGHIncus vulnerable to local privilege escalation through custom storage volumesEPSS 0.2%CVE-2026-16874HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2023-41784MEDIUMPermissions and Access Control Vulnerability in ZTE Red Magic 8 ProEPSS 0.2%CVE-2026-76259HIGHImproper Privilege Management on the Management Port in Splunk Enterprise for WindowsEPSS 0.2%CVE-2026-28919HIGHA consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS TahoEPSS 0.2%CVE-2022-25631HIGHSymantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a tEPSS 0.2%CVE-2022-46334HIGHProofpoint Enterprise Protection Local Privilege EscalationEPSS 0.2%CVE-2026-29111MEDIUMsystemd: Local unprivileged user can trigger an assertEPSS 0.2%CVE-2017-6894HIGHA vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that aEPSS 0.2%CVE-2025-13918MEDIUMElevation of Privileges in Symantec Endpoint Protection Windows ClientEPSS 0.2%