Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-39118HIGHAn issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke EPSS 0.2%CVE-2026-53565HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2026-0275LOWPrisma Browser: Local Privilege Escalation on macOSEPSS 0.2%CVE-2023-25011HIGHPC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the registry as administrEPSS 0.2%CVE-2025-0327HIGHCWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting asEPSS 0.2%CVE-2026-8069HIGHPredatorSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2024-11128HIGHInsufficient Hardened Runtime or Library Validation signing in Bitdefender Virus Scanner for macOSEPSS 0.2%CVE-2025-48982HIGHThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restEPSS 0.2%CVE-2023-34045MEDIUMVMware Fusion installer local privilege escalationEPSS 0.2%CVE-2025-29999MEDIUMA vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable EPSS 0.2%CVE-2026-46680HIGHcontainerd user ID handling bypass allows runAsNonRoot evasionEPSS 0.2%CVE-2023-50700HIGHInsecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged uEPSS 0.2%CVE-2024-23620HIGHIBM Merge Healthcare eFilm Workstation SYSTEM Privilege EscalationEPSS 0.2%CVE-2026-14961MEDIUMCVE-2026-14961EPSS 0.2%CVE-2025-59094HIGHLocal Privilege Escalation in dormakaba Kaba exos 9300 System managementEPSS 0.2%CVE-2024-33656HIGHMemory Leak in SmmComuptrace ModuleEPSS 0.2%CVE-2026-94425CRITICALMoore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges managementEPSS 0.2%CVE-2026-82807CRITICALieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges managementEPSS 0.2%CVE-2026-18606HIGHRazer RzUpdateService Named Pipe RzUpdateService.exe privileges managementEPSS 0.2%CVE-2025-67246HIGHA local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handlerEPSS 0.2%