Weaknesses of type CWE-269

2,489 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2022-48365HIGHAn issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.EPSS 0.9%CVE-2020-12528MEDIUMAn issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access valEPSS 0.9%CVE-2020-12519HIGHPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use this vulnerability i.e. to open a reverse shell with root privileges.EPSS 0.9%CVE-2024-37726MEDIUMInsecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privilegesEPSS 0.9%CVE-2017-9940—A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-prEPSS 0.9%CVE-2023-3636HIGHWP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege EscalationEPSS 0.9%CVE-2022-3422CRITICALImproper Privilege Management in tooljet/tooljetEPSS 0.9%CVE-2023-34465CRITICALXWiki Platform's Mail.MailConfig can be edited by any user with edit rightsEPSS 0.9%CVE-2021-31937HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-44809—D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.EPSS 0.9%CVE-2025-22254MEDIUMAn Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6,EPSS 0.8%CVE-2017-20023MEDIUMSolare Solar-Log Network Config privileges managementEPSS 0.8%CVE-2024-33894HIGHInsecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing severEPSS 0.8%CVE-2023-4697HIGHImproper Privilege Management in usememos/memosEPSS 0.8%CVE-2022-38757HIGHCVE-2022-38757 ZENworksEPSS 0.8%CVE-2022-39203HIGHParsing issue in matrix-org/node-irc leading to room takeoversEPSS 0.8%CVE-2017-20077MEDIUMHindu Matrimonial Script success_story.php privileges managementEPSS 0.8%CVE-2017-20081MEDIUMHindu Matrimonial Script reports.php privileges managementEPSS 0.8%CVE-2017-20070MEDIUMHindu Matrimonial Script communitymanagement.php privileges managementEPSS 0.8%CVE-2017-20068MEDIUMHindu Matrimonial Script usermanagement.php privileges managementEPSS 0.8%