Weaknesses of type CWE-269

2,528 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-21343—In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of prEPSS 0.1%CVE-2025-69689HIGHThe Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-suEPSS 0.1%CVE-2022-32633MEDIUMIn Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System exeEPSS 0.1%CVE-2026-73747LOWLocal Privilege Escalation Vulnerability in HPE Networking Fabric ComposerEPSS 0.1%CVE-2026-28548HIGHVulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service coEPSS 0.1%CVE-2023-21397—In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of priEPSS 0.1%CVE-2026-7994HIGHInappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level pEPSS 0.1%CVE-2024-31334MEDIUMIn DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This coEPSS 0.1%CVE-2026-11308MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malEPSS 0.1%CVE-2024-40662HIGHIn scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local esEPSS 0.1%CVE-2025-13917HIGHElevation of Privileges in Web Security Services (WSS) AgentEPSS 0.1%CVE-2021-25515MEDIUMAn improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.EPSS 0.1%CVE-2026-96812HIGHHost Root Sandbox Escape in gVisor via Character Device Passthrough and CUSEEPSS 0.1%CVE-2026-0032HIGHIn multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local eEPSS 0.1%CVE-2024-31311MEDIUMIn increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to loEPSS 0.1%CVE-2026-11229MEDIUMInappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation EPSS 0.1%CVE-2026-79153HIGHSeclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that alEPSS 0.1%CVE-2022-22263MEDIUMUnprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.EPSS 0.1%CVE-2023-20995—In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This couEPSS 0.1%CVE-2025-12683MEDIUMNULL DACL assigned to Named Pipe communicating with SYSTEM ServiceEPSS 0.1%