Weaknesses of type CWE-269

2,521 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-0046MEDIUMIn InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attacEPSS 0.1%CVE-2024-24970MEDIUMPotential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software DrivEPSS 0.1%CVE-2026-73725HIGHLocal Privilege Escalation leads to Arbitrary Code Execution in HPE Networking Fabric ComposerEPSS 0.1%CVE-2026-20890HIGHImproper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escEPSS 0.1%CVE-2023-52543MEDIUMPermission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.1%CVE-2025-9038HIGHS1 Agile Privilege EscalationEPSS 0.1%CVE-2026-27456MEDIUMutil-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device SetupEPSS 0.1%CVE-2026-63701MEDIUMDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low priEPSS 0.1%CVE-2026-63700HIGHDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attackEPSS 0.1%CVE-2026-44218LOWciguard: Container image runs as root (no USER directive)EPSS 0.1%CVE-2026-83249HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.1%CVE-2026-0048MEDIUMIn hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This cEPSS 0.1%CVE-2026-83316HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The suppoEPSS 0.1%CVE-2026-83239HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca ApplicEPSS 0.1%CVE-2025-10578MEDIUMHP Support Assistant - Potential Escalation of PrivilegeEPSS 0.1%CVE-2022-20356MEDIUMIn shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due EPSS 0.1%CVE-2025-31272HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protEPSS 0.1%CVE-2025-66265MEDIUMInsecure permissions in configuration directory (C:\\usr)EPSS 0.1%CVE-2020-9222HIGHThere is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need EPSS 0.1%CVE-2026-18107HIGHCriu: criu: container escape via rseq critical section hijack during checkpoint/restoreEPSS 0.1%