Weaknesses of type CWE-269

2,515 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-22621MEDIUMPrivilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAREPSS 0.3%CVE-2023-38496MEDIUMApptainer's ineffective privileges drop when requesting container networkEPSS 0.3%CVE-2024-27207CRITICALExported broadcast receivers allowing malicious apps to bypass broadcast protection.EPSS 0.3%CVE-2024-31320HIGHIn setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation dEPSS 0.3%CVE-2024-3507HIGHPrivilege escalation vulnerability in LunarEPSS 0.3%CVE-2024-27826HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma EPSS 0.3%CVE-2026-83170HIGHVulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are aEPSS 0.3%CVE-2021-25657HIGHAvaya IP Office Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-12405HIGHUnauthorized access through stored credentials in Looker StudioEPSS 0.3%CVE-2026-17952HIGHInappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious eEPSS 0.3%CVE-2024-37364MEDIUMAriane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensiEPSS 0.3%CVE-2020-27352CRITICALWhen generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result sEPSS 0.3%CVE-2024-32849HIGHTrend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionaEPSS 0.3%CVE-2025-50066LOWVulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-1EPSS 0.3%CVE-2022-32782MEDIUMThis issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able tEPSS 0.3%CVE-2022-38777HIGHAn issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate thEPSS 0.3%CVE-2026-92017HIGHPrivilege escalation in the DOM: Service Workers componentEPSS 0.3%CVE-2025-5496LOWArbitrary File DeletionEPSS 0.3%CVE-2022-38775HIGHAn issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate thEPSS 0.3%CVE-2023-38614MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be EPSS 0.3%