Weaknesses of type CWE-269

2,528 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-19915HIGHHP Support Assistant - Local Escalation of PrivilegeEPSS 0.1%CVE-2021-25363MEDIUMAn improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processEPSS 0.1%CVE-2024-31318HIGHIn CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permissioEPSS 0.1%CVE-2024-36499MEDIUMVulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect servicEPSS 0.1%CVE-2024-29741HIGHIn pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2024-51521MEDIUMInput parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affectEPSS 0.1%CVE-2024-40658HIGHIn getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to EPSS 0.1%CVE-2023-21396—In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2023-48406—there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to locaEPSS 0.1%CVE-2021-25513LOWAn improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some dEPSS 0.1%CVE-2021-25362MEDIUMAn improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local filEPSS 0.1%CVE-2026-20246MEDIUMCisco Umbrella Virtual Appliance Privilege Escalation VulnerabilityEPSS 0.1%CVE-2026-12858HIGHLocal privilege escalation vulnerability in ESET AV RemoverEPSS 0.1%CVE-2024-31322MEDIUMIn updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Setting while retaininEPSS 0.1%CVE-2024-23711HIGHIn DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This couldEPSS 0.1%CVE-2023-35676—In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafEPSS 0.1%CVE-2023-21343—In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of prEPSS 0.1%CVE-2025-69689HIGHThe Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-suEPSS 0.1%CVE-2024-31323HIGHIn onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could leadEPSS 0.1%CVE-2022-32633MEDIUMIn Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System exeEPSS 0.1%