Weaknesses of type CWE-269

2,528 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-32345HIGHIn updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary userEPSS 0.1%CVE-2022-36861MEDIUMCustom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystEPSS 0.1%CVE-2023-21068—In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to localEPSS 0.1%CVE-2024-23710HIGHIn assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privilegEPSS 0.1%CVE-2024-32906HIGHIn AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no adEPSS 0.1%CVE-2025-48613HIGHIn VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the EPSS 0.1%CVE-2023-21374—In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of pEPSS 0.1%CVE-2023-35667—In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a lEPSS 0.1%CVE-2023-20680MEDIUMIn adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2026-58874HIGHIn multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead EPSS 0.1%CVE-2025-66324HIGHInput verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affeEPSS 0.1%CVE-2026-0009HIGHIn multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege witEPSS 0.1%CVE-2023-21376MEDIUMIn Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosurEPSS 0.1%CVE-2023-20655HIGHIn mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code execution with no additEPSS 0.1%CVE-2026-0023HIGHIn createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permisEPSS 0.1%CVE-2023-40106HIGHIn sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. ThisEPSS 0.1%CVE-2025-6177HIGHChromeOS MiniOS Root Code Execution Bypass While Dev Mode BlockedEPSS 0.1%CVE-2024-25987MEDIUMIn pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation EPSS 0.1%CVE-2025-26435HIGHIn updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary userEPSS 0.1%CVE-2024-22008HIGHIn config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatEPSS 0.1%