Weaknesses of type CWE-269

2,518 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-27795—An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.EPSS 0.2%CVE-2022-26057MEDIUMMint WorkBench Link Following Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-61413MEDIUMDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A lEPSS 0.2%CVE-2025-31243HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS VenturEPSS 0.2%CVE-2023-27793—An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak encoding of sensitivEPSS 0.2%CVE-2025-43256HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be abEPSS 0.2%CVE-2024-36586HIGHAn issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.EPSS 0.2%CVE-2026-100686HIGHBudibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/appsEPSS 0.2%CVE-2023-47611HIGHA CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, TEPSS 0.2%CVE-2022-23921HIGHICSA-22-053-01 GE Proficy CIMPLICITY-IPMEPSS 0.2%CVE-2024-31556HIGHAn issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessioniEPSS 0.2%CVE-2024-8306HIGHCWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and avaEPSS 0.2%CVE-2023-6119MEDIUM An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain EPSS 0.2%CVE-2026-10217MEDIUMnextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges managementEPSS 0.2%CVE-2025-40594MEDIUMA vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS EPSS 0.2%CVE-2026-17744HIGHInappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially performEPSS 0.2%CVE-2021-31360HIGHJunos OS and Junos OS Evolved: Denial of Service vulnerability in local file processingEPSS 0.2%CVE-2021-37941—A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an applicaEPSS 0.2%CVE-2026-14444HIGHWP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' ParameterEPSS 0.2%CVE-2025-24119HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.7, macOS Ventura 13EPSS 0.2%