Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2022-41835HIGHF5OS vulnerability CVE-2022-41835EPSS 0.2%CVE-2026-31368HIGHPrivilege Bypass in AiAssistantEPSS 0.2%CVE-2025-22231HIGHVMware Aria Operations updates address a local privilege escalation vulnerability (CVE-2025-22231)EPSS 0.2%CVE-2026-28995HIGHA logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOSEPSS 0.2%CVE-2024-2431MEDIUMGlobalProtect App: Local User Can Disable GlobalProtectEPSS 0.2%CVE-2026-15430MEDIUMCVE-2026-15430EPSS 0.2%CVE-2025-1037HIGHBy making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user level shell commands EPSS 0.2%CVE-2025-54821LOWAn Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11EPSS 0.2%CVE-2026-26946MEDIUMDell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerabEPSS 0.2%CVE-2026-26947MEDIUMDell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulneraEPSS 0.2%CVE-2023-51429MEDIUM Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. EPSS 0.2%CVE-2026-12502HIGHLoytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudoEPSS 0.2%CVE-2026-49501MEDIUMDell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vuEPSS 0.2%CVE-2026-84083HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.2%CVE-2025-6943LOWSecret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to rEPSS 0.2%CVE-2025-49156HIGHA link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected insEPSS 0.2%CVE-2023-40685HIGHIBM i privilege escalationEPSS 0.1%CVE-2026-29121HIGH`/sbin/ip` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPEEPSS 0.1%CVE-2026-28889MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary fileEPSS 0.1%CVE-2026-73713HIGHLocal Privilege Escalation Vulnerabilities in HPE Networking Fabric ComposerEPSS 0.1%