Weaknesses of type CWE-269

2,510 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-8660MEDIUMPrivilege Escalation in Symantec PGP Encryption 11.0.1EPSS 0.3%CVE-2023-23428LOW Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2026-8327MEDIUMConcrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.EPSS 0.3%CVE-2023-25144HIGHAn improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and creaEPSS 0.3%CVE-2024-41228HIGHA symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges anEPSS 0.3%CVE-2024-6325MEDIUMRockwell Automation Unsecured Private Keys in FactoryTalk® System ServicesEPSS 0.3%CVE-2025-58053MEDIUMGalette has a privilege escalation vulnerabilityEPSS 0.3%CVE-2026-43886HIGHOutline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API AccessEPSS 0.3%CVE-2026-17472CRITICALMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.3%CVE-2026-50295MEDIUMWindows Zero Trust DNS Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2025-26705MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.3%CVE-2025-5689HIGHImproper Permission Management in SSH Session HandlingEPSS 0.3%CVE-2026-33552LOWNorthern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.EPSS 0.3%CVE-2025-4085HIGHPotential information leakage and privilege escalation in UITour actorEPSS 0.3%CVE-2022-42796HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be aEPSS 0.3%CVE-2025-24863MEDIUMImproper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow aEPSS 0.3%CVE-2026-62565HIGHVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affeEPSS 0.3%CVE-2020-7254HIGHPrivilege escalation in Advanced Threat DefenseEPSS 0.3%CVE-2026-15354CRITICALACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' ParameterEPSS 0.3%CVE-2026-1566HIGHLatePoint <= 5.2.7 - Authenticated (Agent+) Privilege EscalationEPSS 0.3%