Weaknesses of type CWE-269

2,517 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-26314HIGHImproper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary coEPSS 0.2%CVE-2021-25418—Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrarEPSS 0.2%CVE-2025-26396HIGHSolarWinds Dameware Mini Remote Control Service Incorrect Permissions Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-32955MEDIUMHarden-Runner Evasion of 'disable-sudo' policyEPSS 0.2%CVE-2026-19423HIGHUltimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile FormsEPSS 0.2%CVE-2020-15934HIGHAn execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. mEPSS 0.2%CVE-2026-11108HIGHInappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalaEPSS 0.2%CVE-2026-21983HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2023-52093HIGHAn exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affecteEPSS 0.2%CVE-2024-6677HIGHPrivilege escalation in uberAgentEPSS 0.2%CVE-2022-27677HIGH Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentialEPSS 0.2%CVE-2020-12615—An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and speciEPSS 0.2%CVE-2023-5847MEDIUM Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privilegEPSS 0.2%CVE-2024-36056MEDIUMHw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory via IOCTL 0x9c40649EPSS 0.2%CVE-2024-0049HIGHIn multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privileEPSS 0.2%CVE-2026-100611HIGHCapgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-listEPSS 0.2%CVE-2025-27644HIGHVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-0EPSS 0.2%CVE-2023-21512LOWImproper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notiEPSS 0.2%CVE-2025-43188HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gaEPSS 0.2%CVE-2023-48418CRITICALUser Build misconfiguration resulting in local escalation of privilegeEPSS 0.2%