Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-24286HIGHA vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.EPSS 19.1%CVE-2023-40289HIGHA command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevatEPSS 17.8%CVE-2023-2833HIGHReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege EscalationEPSS 17.5%CVE-2024-5009HIGHWhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation VulnerabilityEPSS 17.4%CVE-2025-47411HIGHApache StreamPipes: Leverage of User ID for Privilege EscalationEPSS 16.2%CVE-2023-20048CRITICALA vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacEPSS 15.8%CVE-2023-38944CRITICALAn issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access EPSS 15.5%CVE-2021-1388CRITICALCisco ACI Multi-Site Orchestrator Application Services Engine Deployment Authentication Bypass VulnerabilityEPSS 14.8%CVE-2024-12284HIGHAuthenticated privilege escalationEPSS 13.3%CVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 13.0%KEVCVE-2013-0643HIGHThe Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 anEPSS 10.5%KEVCVE-2017-7922An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly rEPSS 9.6%CVE-2025-8489CRITICALKing Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege EscalationEPSS 9.3%CVE-2024-29976MEDIUM** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware vEPSS 9.0%CVE-2019-1388HIGHAn elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'WinEPSS 8.6%KEVCVE-2023-28434HIGHMinIO is vulnerable to privilege escalation on Linux/MacOSEPSS 7.9%KEVCVE-2026-62145HIGHLocal Privilege Escalation in Gaia PortalEPSS 7.6%CVE-2020-3950HIGHVMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior bEPSS 7.3%KEVCVE-2025-4601HIGHRH - Real Estate WordPress Theme <= 4.4.0 - Authenticated (Subscriber+) Privilege EscalationEPSS 7.0%CVE-2021-30355Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilegeEPSS 6.9%