Weaknesses of type CWE-269

2,488 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2021-36307HIGHNetworking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low prEPSS 0.9%CVE-2021-36784HIGHPrivilege escalation for users with create/update permissions in Global RolesEPSS 0.9%CVE-2018-14808—Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on the affected productEPSS 0.9%CVE-2021-24158—Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege EscalationEPSS 0.9%CVE-2023-44250HIGHAn improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a ForEPSS 0.9%CVE-2025-59693CRITICALThe Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) EPSS 0.9%CVE-2023-27589MEDIUMMinio vulnerable to denial of access by an admin privileged user for root credentialEPSS 0.9%CVE-2022-26668HIGHASUS Control Center - Broken Access ControlEPSS 0.9%CVE-2022-42459HIGHWordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Auth. WordPress Options Change vulnerabilityEPSS 0.9%CVE-2024-36439CRITICALSwissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash EPSS 0.9%CVE-2022-39202MEDIUMIRC mode parameter confusion in matrix-appservice-ircEPSS 0.9%CVE-2019-1162HIGHWindows ALPC Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-1762HIGHImproper Privilege Management in thorsten/phpmyfaqEPSS 0.9%CVE-2023-1326HIGHlocal privilege escalation in apport-cliEPSS 0.9%CVE-2021-31350HIGHJunos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)EPSS 0.9%CVE-2025-47955HIGHWindows Remote Access Connection Manager Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-40484CRITICALChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore FunctionEPSS 0.9%CVE-2017-20063MEDIUMElefant CMS File Upload drop privileges managementEPSS 0.9%CVE-2022-45608—An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and EPSS 0.9%CVE-2023-37859HIGHPHOENIX CONTACT: Improper Privilege Management in WP 6xxx Web panelsEPSS 0.9%