Weaknesses of type CWE-269

2,510 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-73758MEDIUMAuthenticated Privilege Escalation Vulnerability via Broken Access Control in AOS-CXEPSS 0.3%CVE-2026-13598CRITICALRestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to AdministratorEPSS 0.3%CVE-2025-50065LOWVulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version that is affected isEPSS 0.3%CVE-2026-64753MEDIUMA permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden GateEPSS 0.3%CVE-2026-73730MEDIUMAuthenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2025-0651MEDIUMFile symlink abuse might lead to deleting files belonging to SYSTEM userEPSS 0.3%CVE-2024-33500HIGHA vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (VEPSS 0.3%CVE-2026-50343HIGHMicrosoft Install Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-34754MEDIUMA CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected PrEPSS 0.3%CVE-2026-50391HIGHWindows Group Policy Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2013-4536—An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process EPSS 0.3%CVE-2026-0912HIGHToret Manager <= 1.2.7 - Authenticated (Subscriber+) Arbitrary Options Update via AJAX actionsEPSS 0.3%CVE-2025-37101HIGHHPE OneView for VMware vCenter (OV4VC), Local Elevation of PrivilegeEPSS 0.3%CVE-2026-16371HIGHPrivilege escalation in the DOM: Navigation componentEPSS 0.3%CVE-2026-81583MEDIUMTheme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege EscalationEPSS 0.3%CVE-2026-16372HIGHPrivilege escalation in the DOM: Content Processes componentEPSS 0.3%CVE-2017-20107MEDIUMShadeYouVPN.com Client privileges managementEPSS 0.3%CVE-2026-55225HIGHStrimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`EPSS 0.3%CVE-2023-46277—please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX arEPSS 0.3%CVE-2023-20854HIGHVMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine mEPSS 0.3%