Weaknesses of type CWE-269

2,528 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-26435HIGHIn updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary userEPSS 0.1%CVE-2024-22008HIGHIn config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatEPSS 0.1%CVE-2026-28586LOWIn multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to loEPSS 0.1%CVE-2024-32918MEDIUMPermission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization stepsEPSS 0.1%CVE-2024-23713HIGHIn migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to impropEPSS 0.1%CVE-2025-6182HIGHRoot Certificate InjectionEPSS 0.1%CVE-2024-34743HIGHIn setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could leaEPSS 0.1%CVE-2024-38487HIGHapi-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintendEPSS 0.1%CVE-2024-29784HIGHIn prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escaEPSS 0.1%CVE-2024-27233HIGHIn ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of EPSS 0.1%CVE-2026-16923HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-0019HIGHIn SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation oEPSS 0.1%CVE-2026-11276MEDIUMInappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discEPSS 0.1%CVE-2026-11103HIGHInappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level prEPSS 0.1%CVE-2024-27224HIGHIn strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of priviEPSS 0.1%CVE-2024-27222HIGHIn onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GREPSS 0.1%CVE-2024-27210HIGHIn policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privEPSS 0.1%CVE-2024-40657HIGHIn addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused depuEPSS 0.1%CVE-2024-32899HIGHIn gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could EPSS 0.1%CVE-2024-25990MEDIUMIn pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This coEPSS 0.1%