Weaknesses of type CWE-269

2,528 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-0086MEDIUMIn onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could leaEPSS 0.1%CVE-2024-49742HIGHIn onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings dueEPSS 0.1%CVE-2026-0179MEDIUMIn Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege witEPSS 0.1%CVE-2024-34725HIGHIn DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to locaEPSS 0.1%CVE-2026-0016LOWIn updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a peEPSS 0.1%CVE-2021-25502HIGHA vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESEPSS 0.1%CVE-2026-0050LOWIn handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This couEPSS 0.1%CVE-2026-0091HIGHIn multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could leadEPSS 0.1%CVE-2026-0089HIGHIn multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check.EPSS 0.1%CVE-2024-29779HIGHthere is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additionaEPSS 0.1%CVE-2026-16742MEDIUMsystemd-homed: local privilege escalation via missing home-record signature verification on the authenticate pathEPSS 0.1%CVE-2026-100820HIGHPrivilege escalation in the Address Bar componentEPSS —CVE-2026-100807HIGHPrivilege escalation in the DOM: Service Workers componentEPSS —CVE-2026-102676HIGHElectron: <webview> can enable Node.js integration in Web Workers despite embedder restrictionsEPSS —CVE-2026-102112HIGHKiteworks Core Local Privilege EscalationEPSS —CVE-2026-102141MEDIUMKiteworks Core Privilege Escalation through External Control of File Name or PathEPSS —CVE-2026-53605HIGHReachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl GrantEPSS —CVE-2026-75823HIGHWP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role EncryptionEPSS —CVE-2026-102120HIGHKiteworks Core OS Command InjectionEPSS —CVE-2026-76732MEDIUMAuthenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ONEPSS —