Weaknesses of type CWE-269

2,489 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2022-33640HIGHSystem Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-23093HIGHThe Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authentEPSS 0.6%CVE-2025-12485HIGHImproper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonateEPSS 0.6%CVE-2024-35430HIGHIn ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data froEPSS 0.6%CVE-2025-47849HIGHApache CloudStack: Insecure access of user's API/Secret Keys in the same domainEPSS 0.6%CVE-2025-47713HIGHApache CloudStack: Domain Admin can reset Admin password in Root DomainEPSS 0.6%CVE-2021-23265LOWImproper Privilege Management in Crafter StudioEPSS 0.6%CVE-2024-31502HIGHAn issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /adEPSS 0.6%CVE-2024-45041HIGHExternal Secrets Operator vulnerable to privilege escalationEPSS 0.6%CVE-2024-3325HIGHJasperReports Server Driver upload vulnerabilityEPSS 0.6%CVE-2020-8290—Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack EPSS 0.6%CVE-2024-21622MEDIUMCraft CMS Privilege EscalationEPSS 0.6%CVE-2024-3470MEDIUMRepository administrator can bypass organization's ruleset using deploy keysEPSS 0.6%CVE-2026-14482HIGH多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'value' ParametersEPSS 0.6%CVE-2024-22157CRITICALWordPress SalesKing plugin <= 1.6.15 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.6%CVE-2026-36213HIGHAn issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.EPSS 0.6%CVE-2022-46410HIGHAn issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root byEPSS 0.6%CVE-2021-37911HIGHThe management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any syEPSS 0.6%CVE-2023-51425CRITICALWordPress Rencontre plugin <= 3.10.1 - Unauthenticated Account Takeover vulnerabilityEPSS 0.6%CVE-2024-29052HIGHWindows Storage Elevation of Privilege VulnerabilityEPSS 0.6%