Weaknesses of type CWE-269

2,521 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-21114HIGHIn multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege withEPSS 0.1%CVE-2025-50892HIGHThe eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges for I/O requests (IRPEPSS 0.1%CVE-2025-26513HIGHThe installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited cEPSS 0.1%CVE-2024-57062MEDIUMAn issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the sessEPSS 0.1%CVE-2023-21113HIGHIn multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege withEPSS 0.1%CVE-2025-10650LOWImproper SSH Key Handling in Internal Debug Builds May Grant Cluster-Level Access to Non-Administrative UsersEPSS 0.1%CVE-2024-0046HIGHIn installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the codEPSS 0.1%CVE-2026-2640MEDIUMDuring an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticatedEPSS 0.1%CVE-2025-9059HIGHElevation of Privileges Vulnerability in IT Management SuiteEPSS 0.1%CVE-2026-23772HIGHDell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A loEPSS 0.1%CVE-2026-17438MEDIUMIBM i is Affected By An Improper Privilege Management Vulnerability in LDAP []EPSS 0.1%CVE-2026-45256MEDIUMMissing permission check in thr_kill2(2)EPSS 0.1%CVE-2022-24931HIGHImproper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to exeEPSS 0.1%CVE-2024-13975HIGHCommvault 11.20.0 - 11.36.0 Windows Access Nodes Compromise via Local File Server Agent AbuseEPSS 0.1%CVE-2026-9490MEDIUMAcer Care Center creates a Named Pipe with a weak Security DescriptorEPSS 0.1%CVE-2025-43019MEDIUMHP Support Assistant – Potential Escalation of PrivilegeEPSS 0.1%CVE-2026-32802MEDIUMDell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with locaEPSS 0.1%CVE-2025-24006HIGHPrivilege Escalation via Insecure SSH PermissionsEPSS 0.1%CVE-2026-32323HIGHMullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installerEPSS 0.1%CVE-2024-24970MEDIUMPotential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software DrivEPSS 0.1%