Weaknesses of type CWE-269

2,489 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-9192HIGHWP Video Robot <= 1.20.0 - Authenticated (Subscriber+) Privilege Escalation via User Meta UpdateEPSS 0.6%CVE-2019-3786HIGHBBR could run arbitrary scripts on deployment VMsEPSS 0.6%CVE-2026-2631CRITICALDatalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2023-39734—The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token anEPSS 0.6%CVE-2022-24072—The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store weEPSS 0.6%CVE-2022-41268HIGHIn some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200EPSS 0.6%CVE-2026-13228HIGHLatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' ParameterEPSS 0.6%CVE-2023-39732—The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broaEPSS 0.6%CVE-2023-39740—The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadEPSS 0.6%CVE-2026-66818HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-12981CRITICALListee <= 1.1.6 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2026-61781CRITICALpg_partman has privilege escalation through SQL injection in create_partition_time()EPSS 0.6%CVE-2020-13519HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/EPSS 0.6%CVE-2024-33552CRITICALWordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerabilityEPSS 0.6%CVE-2022-3641HIGHElevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated useEPSS 0.6%CVE-2023-39733—The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mEPSS 0.6%CVE-2024-2433MEDIUMPAN-OS: Improper Privilege Management Vulnerability in Panorama Software Leads to Availability LossEPSS 0.6%CVE-2024-31498HIGHYubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windoEPSS 0.6%CVE-2023-46145HIGHWordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerabilityEPSS 0.6%CVE-2025-57118CRITICALAn issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.phpEPSS 0.6%