Weaknesses of type CWE-269

2,518 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-48418CRITICALUser Build misconfiguration resulting in local escalation of privilegeEPSS 0.2%CVE-2022-32900HIGHA logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be abEPSS 0.2%CVE-2024-21966HIGHA DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resultiEPSS 0.2%CVE-2025-53029LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2023-37925MEDIUMAn improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEEPSS 0.2%CVE-2024-44439MEDIUMAn issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allowsEPSS 0.2%CVE-2022-43533HIGH A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A suEPSS 0.2%CVE-2022-43534HIGHA vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A sucEPSS 0.2%CVE-2025-12425CRITICALLocal Privilege EscalationEPSS 0.2%CVE-2023-5960MEDIUMAn improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VEPSS 0.2%CVE-2025-36891HIGHElevation of privilegeEPSS 0.2%CVE-2021-27445HIGHMesa Labs AmegaView Improper Privilege ManagementEPSS 0.2%CVE-2021-23887HIGHPrivilege escalation in McAfee DLP Endpoint for WindowsEPSS 0.2%CVE-2024-28241HIGHGlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folderEPSS 0.2%CVE-2026-84358MEDIUMImproper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2024-12786HIGHX1a0He Adobe Downloader XPC Service com.x1a0he.macOS.Adobe-Downloader.helper shouldAcceptNewConnection privileges managementEPSS 0.2%CVE-2024-44540MEDIUMUbiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART DeEPSS 0.2%CVE-2024-43446LOWImproper check of permissions in Generic InterfaceEPSS 0.2%CVE-2025-43248HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may EPSS 0.2%CVE-2021-22733—Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access EPSS 0.2%