Weaknesses of type CWE-269

2,488 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-22946MEDIUMApache Spark proxy-user privilege escalation from malicious configuration classEPSS 1.1%CVE-2024-23537HIGHApache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role.EPSS 1.1%CVE-2022-2104CRITICALSecheron SEPCOS Control and Protection RelayEPSS 1.1%CVE-2024-43199HIGHNagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.EPSS 1.1%CVE-2023-36024HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2023-31469HIGHApache StreamPipes: Privilege escalation through non-admin userEPSS 1.1%CVE-2024-34370HIGHWordPress EAN for WooCommerce plugin <= 4.8.9 - Arbitrary Option Update to Privilege Escalation vulnerabilityEPSS 1.1%CVE-2021-23885CRITICALPrivilege escalation vulnerability in McAfee Web Gateway (MWG) UIEPSS 1.1%CVE-2022-38351HIGHA vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUEPSS 1.1%CVE-2021-3813MEDIUMImproper Privilege Management in chatwoot/chatwootEPSS 1.1%CVE-2026-0920CRITICALLA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameterEPSS 1.1%CVE-2023-43317HIGHAn issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session StoragEPSS 1.1%CVE-2023-27830CRITICALTightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted filEPSS 1.1%CVE-2023-4822MEDIUMGrafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations,EPSS 1.1%CVE-2017-20025HIGHSolare Solar-Log Flash Memory privileges managementEPSS 1.1%CVE-2017-20111HIGHTeleopti WFM Administration privileges managementEPSS 1.1%CVE-2022-35768HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2026-84830HIGHOS command injection in privileged configuration handlingEPSS 1.1%CVE-2025-29800HIGHMicrosoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2022-20347HIGHIn onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remEPSS 1.1%