Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-7493CRITICALWPCOM Member <= 1.5.2.1 - Unauthenticated Privilege Escalation via User MetaEPSS 0.6%CVE-2026-16850HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.6%CVE-2024-27710CRITICALAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentiEPSS 0.6%CVE-2024-28391CRITICALSQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate EPSS 0.6%CVE-2024-3828HIGHSpectra Pro <= 1.1.5 - Authenticated (Author+) Privilege EscalationEPSS 0.6%CVE-2024-21892HIGHOn Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running withEPSS 0.6%CVE-2024-30007HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-26369HIGHJUNG eNet SMART HOME server 2.2.1/2.3.1 Privilege Escalation via setUserGroupEPSS 0.6%CVE-2025-3278CRITICALUrbanGo Membership <= 1.0.4 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2026-69414HIGHMicrosoft Defender Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-38775HIGHWordPress CTX Feed plugin <= 6.5.6 - Arbitrary Options Update vulnerabilityEPSS 0.6%CVE-2024-27811CRITICALThe issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, wEPSS 0.6%CVE-2024-11721HIGHFrontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2023-6793LOWPAN-OS: XML API Keys Revoked by Read-Only PAN-OS AdministratorEPSS 0.6%CVE-2024-22264HIGHVMware Avi Load Balancer updates address multiple vulnerabilitiesEPSS 0.6%CVE-2023-48757HIGHWordPress JetEngine plugin <= 3.2.4 - Privilege Escalation vulnerabilityEPSS 0.6%CVE-2023-32196HIGHRancher's External RoleTemplates can lead to privilege escalationEPSS 0.6%CVE-2023-51356HIGHWordPress ARMember plugin <= 4.0.10 - Privilege Escalation vulnerabilityEPSS 0.6%CVE-2024-0353HIGHLocal privilege escalation in Windows productsEPSS 0.6%CVE-2023-47132CRITICALAn issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.EPSS 0.6%