Weaknesses of type CWE-269

2,489 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-28399CRITICALAn issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address ControlEPSS 0.6%CVE-2023-28855MEDIUMFields GLPI plugin vulnerable to unauthorized write access to additional fieldsEPSS 0.6%CVE-2023-29166—A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate prEPSS 0.6%CVE-2024-29667CRITICALSQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate priEPSS 0.6%CVE-2021-34487HIGHWindows Event Tracing Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-0222HIGHA CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the contEPSS 0.6%CVE-2024-1908MEDIUMImproper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege EscalationEPSS 0.6%CVE-2023-36569HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-27518HIGHAn issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a cEPSS 0.6%CVE-2024-8100HIGHOn affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.EPSS 0.6%CVE-2024-44076CRITICALIn Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.EPSS 0.6%CVE-2024-9941HIGHWPGYM <= 67.1.0 - Missing Authorization to Authenticated (Subscriber+) Privilege EscalationEPSS 0.6%CVE-2022-41604HIGHCheck Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissiEPSS 0.6%CVE-2022-20739HIGHCisco SD-WAN vManage Software Privilege Escalation VulnerabilityEPSS 0.6%CVE-2026-52533CRITICALAn issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component fileEPSS 0.6%CVE-2022-26795HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-33398HIGHThere is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to imEPSS 0.6%CVE-2026-59245HIGHApache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)EPSS 0.6%CVE-2023-41957HIGHWordPress Simple Membership plugin <= 4.3.4 - Unauthenticated Membership Role Privilege Escalation vulnerabilityEPSS 0.6%CVE-2022-33640HIGHSystem Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege VulnerabilityEPSS 0.6%