Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2021-25429—Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to accessEPSS 0.2%CVE-2026-37525HIGHAGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_sEPSS 0.2%CVE-2026-60837HIGHVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.2%CVE-2026-82671MEDIUMIObit Unlocker IRP_MJ_DEVICE_CONTROL IObitUnlocker.sys ZwTerminateProcess privileges managementEPSS 0.2%CVE-2023-20216MEDIUMA vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker EPSS 0.2%CVE-2023-51435HIGH Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. EPSS 0.2%CVE-2025-4636HIGHLocal Privilege EscalationEPSS 0.2%CVE-2024-0833HIGHPrivilege Elevation via Telerik Test StudioEPSS 0.2%CVE-2024-25961MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attaEPSS 0.2%CVE-2024-37126MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacEPSS 0.2%CVE-2024-44097CRITICALAccording to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validaEPSS 0.2%CVE-2026-9489HIGHNitroSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2026-70495HIGHSearch-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:mastersEPSS 0.2%CVE-2025-13176HIGHLocal privilege escalation in ESET Inspect Connector for WindowsEPSS 0.2%CVE-2022-45452HIGHLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 304EPSS 0.2%CVE-2024-32854MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attackEPSS 0.2%CVE-2024-37133MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacEPSS 0.2%CVE-2025-36901HIGHWLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.EPSS 0.2%CVE-2023-28122HIGHA local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with locEPSS 0.2%CVE-2026-83598HIGHNetdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI RepairEPSS 0.2%