Weaknesses of type CWE-269

2,044 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2017-5689CRITICALAn unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AEPSS 92.2%KEVCVE-2024-21888HIGHA privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a useEPSS 86.8%CVE-2022-0441MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account CreationEPSS 85.3%CVE-2021-20021CRITICALA vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a craftedEPSS 83.4%KEVCVE-2021-38540Apache Airflow: Variable Import endpoint missed authentication checkEPSS 80.9%CVE-2021-34621CRITICALProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege EscalationEPSS 68.9%CVE-2023-26475CRITICALXWiki Platform vulnerable to Remote Code Execution in AnnotationsEPSS 63.6%CVE-2016-0151HIGHThe Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold EPSS 63.2%KEVCVE-2020-8655HIGHAn issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apachEPSS 60.1%KEVCVE-2023-22809HIGHIn Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDEPSS 55.4%CVE-2021-43858HIGHUser privilege escalation in MinIOEPSS 35.5%CVE-2024-24747HIGHMinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalationEPSS 34.1%CVE-2023-41326HIGHAccount takeover via Kanban feature in GLPIEPSS 31.0%CVE-2019-1405HIGHAn elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creationEPSS 29.9%KEVCVE-2025-34143CRITICALETQ Reliance CG Authentication Bypass via Trailing Space RCEEPSS 29.9%CVE-2020-17103HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 26.5%CVE-2025-20282CRITICALCisco ISE API Unauthenticated Remote Code Execution VulnerabilityEPSS 26.5%CVE-2025-6934CRITICALOpal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'EPSS 24.3%CVE-2026-1492CRITICALUser Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership RegistrationEPSS 24.2%CVE-2019-1215HIGHAn elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of PrEPSS 19.3%KEV