Weaknesses of type CWE-269

2,515 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-0358HIGHDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration fraEPSS 0.2%CVE-2026-46424MEDIUMBudibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 HourEPSS 0.2%CVE-2021-43768MEDIUMIn Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface runnEPSS 0.2%CVE-2025-57759MEDIUMContao has improper privilege management for page and article fieldsEPSS 0.2%CVE-2025-26703MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.2%CVE-2023-25647MEDIUMPermission and Access Control Vulnerability in Some ZTE Mobile PhonesEPSS 0.2%CVE-2023-3514HIGHRazerCentralSerivce Unsafe Named Pipe Permission Escalation of Privilege VulnerabilityEPSS 0.2%CVE-2020-7273MEDIUMAutorun registry bypassEPSS 0.2%CVE-2024-22237HIGHAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for NetworksEPSS 0.2%CVE-2020-7281HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.2%CVE-2026-100586HIGHOpenClaw Codex before 2026.7.1 Authorization Bypass via BindEPSS 0.2%CVE-2021-3808HIGHPotential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary EPSS 0.2%CVE-2021-3809HIGHPotential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary EPSS 0.2%CVE-2025-6759HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2023-52431HIGHThe Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form valEPSS 0.2%CVE-2021-31359HIGHJunos OS and Junos OS Evolved: Local Privilege Escalation vulnerabilityEPSS 0.2%CVE-2025-27468HIGHWindows Kernel-Mode Driver Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2022-38774HIGHAn issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivilegEPSS 0.2%CVE-2025-36896CRITICALWLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.EPSS 0.2%CVE-2026-73779HIGHAuthentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CXEPSS 0.2%