Weaknesses of type CWE-269

2,489 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2017-20072MEDIUMHindu Matrimonial Script generalsettings.php privileges managementEPSS 0.8%CVE-2017-20068MEDIUMHindu Matrimonial Script usermanagement.php privileges managementEPSS 0.8%CVE-2017-20081MEDIUMHindu Matrimonial Script reports.php privileges managementEPSS 0.8%CVE-2017-20080MEDIUMHindu Matrimonial Script googleads.php privileges managementEPSS 0.8%CVE-2017-20073MEDIUMHindu Matrimonial Script cms.php privileges managementEPSS 0.8%CVE-2017-20070MEDIUMHindu Matrimonial Script communitymanagement.php privileges managementEPSS 0.8%CVE-2017-20077MEDIUMHindu Matrimonial Script success_story.php privileges managementEPSS 0.8%CVE-2017-20071MEDIUMHindu Matrimonial Script renewaldue.php privileges managementEPSS 0.8%CVE-2017-20075MEDIUMHindu Matrimonial Script payment.php privileges managementEPSS 0.8%CVE-2017-20076MEDIUMHindu Matrimonial Script searchview.php privileges managementEPSS 0.8%CVE-2024-57602CRITICALAn issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.EPSS 0.8%CVE-2021-25508MEDIUMImproper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key withouEPSS 0.8%CVE-2023-45581HIGHAn improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an EPSS 0.8%CVE-2023-41955HIGHWordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerabilityEPSS 0.8%CVE-2025-22829LOWApache CloudStack: Unauthorised access to dedicated resources in Quota pluginEPSS 0.8%CVE-2023-0101HIGHA privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attEPSS 0.8%CVE-2022-4314MEDIUMImproper Privilege Management in ikus060/rdiffwebEPSS 0.8%CVE-2026-73218HIGHCursor: Sandbox escape via launching privileged containersEPSS 0.8%CVE-2021-27661HIGHFacility ExplorerEPSS 0.8%CVE-2017-20028MEDIUMHumHub privileges managementEPSS 0.8%