Weaknesses of type CWE-269

2,519 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-83118HIGHVulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected arEPSS 0.1%CVE-2026-30902HIGHZoom Clients for Windows - Improper Privilege ManagementEPSS 0.1%CVE-2026-83288HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versionsEPSS 0.1%CVE-2026-64634HIGHA vulnerability allowing local privilege escalation to the Reporter service context.EPSS 0.1%CVE-2026-83342HIGHVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). SupporteEPSS 0.1%CVE-2026-83353HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.1%CVE-2026-83293HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN). The supported version EPSS 0.1%CVE-2021-3978HIGHImproper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpkiEPSS 0.1%CVE-2026-83317HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Installation). Supported versiEPSS 0.1%CVE-2026-83420HIGHVulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported verEPSS 0.1%CVE-2026-83337HIGHVulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Remote Diagnostic Agent). EPSS 0.1%CVE-2024-31953MEDIUMAn issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used duEPSS 0.1%CVE-2026-83147HIGHVulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported versionEPSS 0.1%CVE-2026-83211HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2026-10610HIGHLocal privilege escalation in ESET security applications for macOSEPSS 0.1%CVE-2023-7343HIGHBelden Industrial HiVision Arbitrary Code Execution via Malicious Project FileEPSS 0.1%CVE-2023-0192MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can leaEPSS 0.1%CVE-2026-65354HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicioEPSS 0.1%CVE-2023-40377MEDIUMIBM i privilege escalationEPSS 0.1%CVE-2023-40378MEDIUMIBM i privilege escalationEPSS 0.1%