Weaknesses of type CWE-269

2,518 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2021-27767MEDIUMHCL BigFix Platform Console is affected by a Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-22235MEDIUMVMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local systemEPSS 0.2%CVE-2020-7523—Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) whichEPSS 0.2%CVE-2026-1726MEDIUMMultiple Vulnerabilities in IBM Guardium Key Lifecycle ManagerEPSS 0.2%CVE-2026-19453HIGHJetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore Admin User SelectionEPSS 0.2%CVE-2022-33962MEDIUMBIG-IP iRule vulnerability CVE-2022-33962EPSS 0.2%CVE-2025-49157HIGHA link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on afEPSS 0.2%CVE-2024-0832HIGHPrivilege Elevation via Telerik Reporting InstallerEPSS 0.2%CVE-2023-30622MEDIUMClusternet has potential risk which can be leveraged to make a cluster-level privilege escalationEPSS 0.2%CVE-2026-89001MEDIUMWPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign SettingsEPSS 0.2%CVE-2025-61759MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2024-34454HIGHNintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a EPSS 0.2%CVE-2025-48645CRITICALIn loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to locaEPSS 0.2%CVE-2025-8453HIGHCWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privilEPSS 0.2%CVE-2024-0082HIGHCVEEPSS 0.2%CVE-2023-34057HIGHVMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elEPSS 0.2%CVE-2025-50061MEDIUMVulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web AccEPSS 0.2%CVE-2024-0096HIGHCVEEPSS 0.2%CVE-2022-27840MEDIUMImproper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsunEPSS 0.2%CVE-2025-50124HIGHA CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a prEPSS 0.2%