Weaknesses of type CWE-269

2,489 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-7080HIGHArbitrary remote code execution within wrangler dev Workers sandboxEPSS 0.6%CVE-2023-48171HIGHAn issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.EPSS 0.6%CVE-2022-32840HIGHThis issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app mayEPSS 0.6%CVE-2023-33966HIGHDeno missing "--allow-net" permission check for built-in Node modulesEPSS 0.6%CVE-2026-76678HIGHAuthenticated Command Injection Vulnerability leads to Remote Code Execution in EdgeConnect SD-WAN GatewaysEPSS 0.6%CVE-2023-28261MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2017-20037MEDIUMSICUNET Access Controller privileges managementEPSS 0.6%CVE-2026-38529HIGHA Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attEPSS 0.6%CVE-2024-22752HIGHInsecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executableEPSS 0.6%CVE-2021-4200MEDIUMWrite access to the Catalog for any user when restricted-admin role is enabledEPSS 0.6%CVE-2026-75977HIGHMang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication CookieEPSS 0.6%CVE-2020-26063MEDIUMCisco Integrated Management Controller Software Authorization Bypass VulnerabilityEPSS 0.6%CVE-2024-9265CRITICALEcho RSS Feed Post Generator <= 5.4.6 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2025-11533CRITICALWP Freeio <= 1.2.21 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2020-36603MEDIUMThe HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calEPSS 0.6%CVE-2022-32829HIGHThis issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to eEPSS 0.6%CVE-2022-41948MEDIUMPrivilege Chaining with the user admin role in dhis2-coreEPSS 0.6%CVE-2021-34579HIGHPHOENIX CONTACT: FL MGUARD DM version 1.12.0 and 1.13.0 Improper Privilege ManagementEPSS 0.6%CVE-2025-29976HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2023-32197HIGHRancher's External RoleTemplates can lead to privilege escalationEPSS 0.6%