Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-0320HIGHCitrix Secure Access - Local Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.1%CVE-2026-15379MEDIUMArbitrary File Read as SYSTEM in Symantec ITMSEPSS 0.1%CVE-2026-9789HIGHNitroSense V3: Security Vulnerability InformationEPSS 0.1%CVE-2026-40002MEDIUMZTE Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations.EPSS 0.1%CVE-2024-49558HIGHDell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerabilityEPSS 0.1%CVE-2024-5760HIGHThe Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shellEPSS 0.1%CVE-2026-60183MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affEPSS 0.1%CVE-2023-1548MEDIUM A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the consEPSS 0.1%CVE-2026-46873HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affecEPSS 0.1%CVE-2026-58583HIGHFluxInk Color Management Driver local privilege escalationEPSS 0.1%CVE-2026-82670MEDIUMIObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges managementEPSS 0.1%CVE-2025-10657HIGHDocker Desktop with ECI Fails to Enforce Socket Command RestrictionsEPSS 0.1%CVE-2023-40686MEDIUMIBM i privilege escalationEPSS 0.1%CVE-2024-31953MEDIUMAn issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used duEPSS 0.1%CVE-2026-83147HIGHVulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported versionEPSS 0.1%CVE-2026-83353HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.1%CVE-2026-83336HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported vEPSS 0.1%CVE-2026-83290HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.1%CVE-2026-83291HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.1%CVE-2026-83342HIGHVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). SupporteEPSS 0.1%