Weaknesses of type CWE-269

2,488 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-36765HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2016-15002HIGHMONyog Ultimate Cookie privileges managementEPSS 1.0%CVE-2022-27487HIGHA improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptorEPSS 1.0%CVE-2021-34766MEDIUMCisco Smart Software Manager Privilege Escalation VulnerabilityEPSS 1.0%CVE-2025-49758HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2026-85979HIGHCommand Injection in Puppet EnterpriseEPSS 1.0%CVE-2026-25770CRITICALWazuh has Privilege Escalation to Root via Cluster Protocol File WriteEPSS 1.0%CVE-2021-36207HIGHMetasys privilege managementEPSS 1.0%CVE-2022-31707HIGHvRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the ImpoEPSS 1.0%CVE-2026-72830HIGHGrav API Plugin before 1.0.13 RCE via ConfigController scope bypassEPSS 0.9%CVE-2022-32801HIGHThis issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to gain root privileges.EPSS 0.9%CVE-2021-36302CRITICALAll Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user EPSS 0.9%CVE-2021-25442—Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.EPSS 0.9%CVE-2023-6099HIGHShenzhen Youkate Industrial Facial Love Cloud Payment System Account SystemMng.ashx privileges managementEPSS 0.9%CVE-2020-12495CRITICALENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege managementEPSS 0.9%CVE-2024-45173HIGHAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MEPSS 0.9%CVE-2024-24892HIGHUnauthorized RCE in migration-toolsEPSS 0.9%CVE-2023-4404CRITICALDonation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege EscalationEPSS 0.9%CVE-2018-25040MEDIUMuTorrent Web HTTP RPC Server privileges managementEPSS 0.9%CVE-2022-29164HIGHPrivilege Escalation in argo-workflowsEPSS 0.9%