Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-26236—An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, EPSS 0.2%CVE-2026-83598HIGHNetdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI RepairEPSS 0.2%CVE-2025-33188HIGHNVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware controls. A successful expEPSS 0.2%CVE-2026-46914HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. EasEPSS 0.2%CVE-2023-50450HIGHAn issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated prEPSS 0.2%CVE-2025-0834HIGHWondershare Dr.Fone Privilege Scalation VulnerabilityEPSS 0.2%CVE-2024-44250HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbEPSS 0.2%CVE-2026-0063CRITICALIn setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the codEPSS 0.2%CVE-2025-24183MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local EPSS 0.2%CVE-2025-25230HIGHOmnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is inEPSS 0.2%CVE-2026-75857HIGHCodeWhale before 0.8.64 Privilege Escalation via exec_shell_interactEPSS 0.2%CVE-2026-34218MEDIUMClearanceKit: Managed and user-defined policy rules not enforced between opfilter start and first policy modificationEPSS 0.2%CVE-2026-28840HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS TahoEPSS 0.2%CVE-2023-40375HIGHIBM i privilege escalationEPSS 0.2%CVE-2023-21458MEDIUMImproper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn offEPSS 0.2%CVE-2024-34741HIGHIn setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaEPSS 0.2%CVE-2026-60847LOWVulnerability in the Oracle Order Entry product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are afEPSS 0.2%CVE-2024-2431MEDIUMGlobalProtect App: Local User Can Disable GlobalProtectEPSS 0.2%CVE-2026-28995HIGHA logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOSEPSS 0.2%CVE-2026-31368HIGHPrivilege Bypass in AiAssistantEPSS 0.2%