Weaknesses of type CWE-269

2,520 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-87240HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.1%CVE-2026-60833HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. DifficEPSS 0.1%CVE-2026-61120HIGHVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.1%CVE-2025-4879HIGHCitrix Workspace App for Windows - Local Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.1%CVE-2026-83150HIGHVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability EPSS 0.1%CVE-2024-5907MEDIUMCortex XDR Agent: Local Privilege Escalation (PE) VulnerabilityEPSS 0.1%CVE-2026-61061HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affEPSS 0.1%CVE-2020-9080HIGHThere is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specifiEPSS 0.1%CVE-2026-60661HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. DiEPSS 0.1%CVE-2025-14252HIGHAn Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, andEPSS 0.1%CVE-2026-22536HIGHPRIVILEGE ESCALATION VIA SUDO COMMANDEPSS 0.1%CVE-2025-36640HIGHLocal Privilege EscalationEPSS 0.1%CVE-2025-5687HIGHLocal privilege escalation vulnerability in Mozilla VPN clients for macOS v2.27.0 and below.EPSS 0.1%CVE-2026-35154MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.1%CVE-2025-5028MEDIUMArbitrary file deletion vulnerability in ESET product installersEPSS 0.1%CVE-2026-17877HIGHInappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level priEPSS 0.1%CVE-2024-0674MEDIUMPrivilege escalation vulnerability in Lamassu Bitcoin ATM Douro machinesEPSS 0.1%CVE-2026-17864HIGHInappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilegEPSS 0.1%CVE-2026-14124HIGHInappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OSEPSS 0.1%CVE-2025-26513HIGHThe installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited cEPSS 0.1%