Weaknesses of type CWE-269

2,516 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-36896CRITICALWLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.EPSS 0.2%CVE-2026-54319MEDIUMDaytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escapeEPSS 0.2%CVE-2022-32794HIGHA logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, mEPSS 0.2%CVE-2022-47505HIGHSolarWinds Platform Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2023-52337HIGHAn improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent EPSS 0.2%CVE-2023-35671—In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number aEPSS 0.2%CVE-2025-66374HIGHCyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of anEPSS 0.2%CVE-2024-50619HIGHVulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access EPSS 0.2%CVE-2026-21957HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-55582MEDIUMD-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries suEPSS 0.2%CVE-2026-92055HIGHPrivilege escalation in the DevTools componentEPSS 0.2%CVE-2026-16396HIGHPrivilege escalation in WebExtensionsEPSS 0.2%CVE-2024-22068MEDIUMWeak Password Vulnerability in ZTE ZSR V2 Intelligent Multi Service RouterEPSS 0.2%CVE-2022-38378MEDIUMAn improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 thrEPSS 0.2%CVE-2026-14359HIGHYITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_userEPSS 0.2%CVE-2026-10868CRITICALMISP user edit endpoint mass assignment vulnerability allows unauthorized user account modificationEPSS 0.2%CVE-2026-15451HIGHMemberPress Corporate Accounts <= 1.5.39 - Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account CreationEPSS 0.2%CVE-2025-53024HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-57396MEDIUMTandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which reEPSS 0.2%CVE-2026-18480HIGHSureCart < 4.6.3 - Subscriber+ Administrator Account TakeoverEPSS 0.2%