Weaknesses of type CWE-269

2,489 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-14262HIGHSimple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' ParameterEPSS 0.7%CVE-2023-37917CRITICALPrivilege Escalation in kubepiEPSS 0.7%CVE-2026-6226HIGHFrontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration InjectionEPSS 0.7%CVE-2023-41324HIGHAccount takeover through API in GLPIEPSS 0.7%CVE-2023-41807CRITICALLinux Local Privilege Escalation Via GoTTY PageEPSS 0.7%CVE-2025-14736CRITICALFrontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form FieldEPSS 0.7%CVE-2023-41322MEDIUMPrivilege Escalation from technician to super-admin in GLPIEPSS 0.7%CVE-2023-23610MEDIUMglpi vulnerable to Unauthorized access to data exportEPSS 0.7%CVE-2025-5491HIGHAcer ControlCenter - Remote Code ExecutionEPSS 0.7%CVE-2023-51424CRITICALWordPress WebinarIgnition plugin <= 3.05.0 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.7%CVE-2021-37938—It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf fileEPSS 0.7%CVE-2024-24830CRITICALOpenObserve Privilege Escalation Vulnerability in Users APIEPSS 0.7%CVE-2022-23737MEDIUMImproper Privilege Management in GitHub Enterprise Server leading to page creation and deletionEPSS 0.7%CVE-2023-43120—An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalatEPSS 0.7%CVE-2019-25151MEDIUMFunnel Builder <= 1.3.0 - Arbitrary Plugin ActivationEPSS 0.7%CVE-2021-37937MEDIUMElasticsearch privilege escalationEPSS 0.7%CVE-2023-41243HIGHWordPress WPvivid Backup Plugin plugin <= 0.9.90 - Privilege Escalation on Staging Environment vulnerabilityEPSS 0.7%CVE-2019-1175HIGHWindows Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2019-1177HIGHWindows Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2024-55949CRITICALPrivilege escalation in IAM import API in MinIOEPSS 0.7%