Weaknesses of type CWE-269

2,518 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-43248HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may EPSS 0.2%CVE-2025-50064MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.2%CVE-2026-16401HIGHPrivilege escalation in the Data Loss Prevention componentEPSS 0.2%CVE-2023-5650MEDIUMAn improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmEPSS 0.2%CVE-2024-22239MEDIUMAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for NetworksEPSS 0.2%CVE-2024-6151HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2023-4936MEDIUMSynaptics-DisplayLink-privilege escalation vulnerability via a dynamic library sideloadingEPSS 0.2%CVE-2022-2975HIGHAvaya Aura Application Enablement Services weak permissions in web applicationEPSS 0.2%CVE-2024-42440MEDIUMZoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Improper Privilege ManagementEPSS 0.2%CVE-2026-20287MEDIUMCisco Identity Services Engine Hardening Release - Improper Privlege Management VulnerabilitiesEPSS 0.2%CVE-2022-38060HIGHA privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sEPSS 0.2%CVE-2023-43506HIGHLocal Privilege Escalation in ClearPass OnGuard Linux AgentEPSS 0.2%CVE-2023-5797MEDIUMAn improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEEPSS 0.2%CVE-2025-52555MEDIUMCephFS Permission Escalation Vulnerability in Ceph Fuse mounted FSEPSS 0.2%CVE-2024-40861HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges.EPSS 0.2%CVE-2025-66173MEDIUMThere is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the sEPSS 0.2%CVE-2024-4395HIGHLack of Client Validation in Jamf Compliance Editor's Helper Service May Result in Privilege EscalationEPSS 0.2%CVE-2026-61413MEDIUMDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A lEPSS 0.2%CVE-2025-31243HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS VenturEPSS 0.2%CVE-2022-24408—A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binaryEPSS 0.2%