Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-73713HIGHLocal Privilege Escalation Vulnerabilities in HPE Networking Fabric ComposerEPSS 0.1%CVE-2026-19220LOWForminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege EscalationEPSS 0.1%CVE-2021-23893HIGHPrivilege Escalation vulnerability in McAfee Drive Encryption (MDE)EPSS 0.1%CVE-2026-6389HIGHIBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerabilityEPSS 0.1%CVE-2026-28889MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary fileEPSS 0.1%CVE-2022-37929MEDIUMImproper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary FlEPSS 0.1%CVE-2026-75777HIGHMultiple vulnerabilities in IBM Aspera Enterprise WebappsEPSS 0.1%CVE-2025-67826HIGHAn issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antiEPSS 0.1%CVE-2024-0622HIGHLocal privilege escalation vulnerability could affect OpenText Operations Agent on Non-Windows platforms. EPSS 0.1%CVE-2023-2847HIGHLocal privilege escalation in ESET products for Linux and MacOSEPSS 0.1%CVE-2023-41099HIGHIn the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regular user to SYSTEM).EPSS 0.1%CVE-2026-38764HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysEPSS 0.1%CVE-2024-0172HIGHDell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated EPSS 0.1%CVE-2026-16607HIGHAuthenticated local root privilege escalation vulnerability in openFT for Linux and Oracle SolarisEPSS 0.1%CVE-2026-84587MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahoeEPSS 0.1%CVE-2026-60886HIGHVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2026-29127CRITICALIncorrect Permission Assignment(777) on `monitor` Users Home Directory Containing SUID Root Binaries in IDC SFX2100EPSS 0.1%CVE-2026-84603MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27, watchOS 27. An appEPSS 0.1%CVE-2024-5760HIGHThe Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shellEPSS 0.1%CVE-2026-60183MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.1%