Weaknesses of type CWE-269

2,518 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-50124HIGHA CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a prEPSS 0.2%CVE-2024-0096HIGHCVEEPSS 0.2%CVE-2022-46356HIGHPotential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, andEPSS 0.2%CVE-2022-46357HIGHPotential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, andEPSS 0.2%CVE-2022-46359HIGHPotential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, andEPSS 0.2%CVE-2022-4294HIGHNorton, Avira, Avast and AVG Antivirus for Windows Privilege EscalationEPSS 0.2%CVE-2022-46358HIGHPotential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, andEPSS 0.2%CVE-2025-4681HIGHImproper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affectEPSS 0.2%CVE-2026-41489HIGHPi-hole: Local privilege escalation via config-controlled path in root-executed service hooksEPSS 0.2%CVE-2025-43320HIGHThe issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app may be able to bypasEPSS 0.2%CVE-2026-60248CRITICALVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.2%CVE-2023-27316HIGHPrivilege Escalation Vulnerability in SnapCenterEPSS 0.2%CVE-2026-35272HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions EPSS 0.2%CVE-2024-8424HIGHWatchGuard Endpoint Protection Privilege Escalation in PSANHost Enables Arbitrary File Delete as SYSTEMEPSS 0.2%CVE-2024-0219HIGHPrivilege Elevation via Telerik JustDecompile InstallerEPSS 0.2%CVE-2025-50674HIGHAn issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowingEPSS 0.2%CVE-2023-51776HIGHImproper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.EPSS 0.2%CVE-2024-11467HIGHOmnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of tEPSS 0.2%CVE-2024-21118MEDIUMVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions thatEPSS 0.2%CVE-2026-7977MEDIUMInappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a EPSS 0.2%