Weaknesses of type CWE-269

2,518 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-53913HIGHCalix GigaCenter ONT (Quantenna SoC) - Excessive PrivilegesEPSS 0.2%CVE-2025-1425MEDIUMFile Read Through Improper Sudo Privilege ManagementEPSS 0.2%CVE-2022-39953HIGHA improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1EPSS 0.2%CVE-2026-52853MEDIUMDocmost: Privilege Escalation - ADMIN Can Invite Users as OWNEREPSS 0.2%CVE-2026-11295HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege esEPSS 0.2%CVE-2024-40462HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE componentEPSS 0.2%CVE-2021-24038—Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged pEPSS 0.2%CVE-2024-40458HIGHAn issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.EPSS 0.2%CVE-2025-64487HIGHOutline is vulnerable to privilege escalation vulnerability in document sharingEPSS 0.2%CVE-2024-40460HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXEEPSS 0.2%CVE-2024-40461HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE componentEPSS 0.2%CVE-2023-6804MEDIUMImproper Privilege Management allows for arbitrary workflows to be runEPSS 0.2%CVE-2024-40459HIGHAn issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager functionEPSS 0.2%CVE-2024-23457HIGHAnti-tampering can be disabled with uninstall password enforcedEPSS 0.2%CVE-2025-1424HIGHPrivilege Escalation Through SUID Binary and Developer ModeEPSS 0.2%CVE-2025-70795MEDIUMSTProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminEPSS 0.2%CVE-2023-25535HIGH Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerabilityEPSS 0.2%CVE-2025-1732MEDIUMAn improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlieEPSS 0.2%CVE-2023-24491HIGH A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with accEPSS 0.2%CVE-2021-20334MEDIUMLocal privilege escalation in MongoDB Compass for WindowsEPSS 0.2%