Weaknesses of type CWE-269

2,489 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2022-35771HIGHWindows Defender Credential Guard Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2023-25701CRITICALWordPress WatchTowerHQ plugin <= 3.6.16 - Privilege EscalationEPSS 0.8%CVE-2025-11561HIGHSssd: sssd default kerberos configuration allows privilege escalation on ad-joined linux systemsEPSS 0.8%CVE-2026-12415CRITICALInvoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' ParameterEPSS 0.8%CVE-2021-27394—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (AllEPSS 0.8%CVE-2024-1442MEDIUMUser with permissions to create a data source can CRUD all data sourcesEPSS 0.8%CVE-2024-9636CRITICALPost Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege EscalationEPSS 0.8%CVE-2021-3919CRITICALA potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege aEPSS 0.8%CVE-2026-8809CRITICALAdvanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' ParameterEPSS 0.8%CVE-2026-22708HIGHCursor has a Terminal Tool Allowlist Bypass via Environment VariablesEPSS 0.8%CVE-2022-39032HIGHSmart eVision - Improper Privilege ManagementEPSS 0.8%CVE-2023-32696HIGHExcessive permissions for ckan userEPSS 0.8%CVE-2024-20374MEDIUMA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower ManagemeEPSS 0.8%CVE-2026-49819CRITICALUpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdEPSS 0.8%CVE-2024-22036CRITICALRancher Remote Code Execution via Cluster/Node DriversEPSS 0.8%CVE-2018-14825—On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OEPSS 0.8%CVE-2024-22922CRITICALAn issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the lEPSS 0.8%CVE-2025-24254HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS VenturaEPSS 0.8%CVE-2023-32244CRITICALWordPress Woodmart Core plugin <= 1.0.36 - Privilege EscalationEPSS 0.8%CVE-2023-4140MEDIUMWP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege EscalationEPSS 0.8%