Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-51483CRITICALWordPress WP Frontend Profile plugin <= 1.3.1 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-9018HIGHEasy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' ParameterEPSS 0.5%CVE-2025-2232CRITICALRealteo - Real Estate Plugin by Purethemes <= 1.2.8 - Authentication Bypass via 'do_register_user'EPSS 0.5%CVE-2020-16126LOWaccountsservice drops ruid, allows unprivileged users to send it signalsEPSS 0.5%CVE-2026-55843HIGHSnipe-IT: Improper Privilege ManagementEPSS 0.5%CVE-2025-52915HIGHK7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminEPSS 0.5%CVE-2024-33374CRITICALIncorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal withEPSS 0.5%CVE-2022-46172MEDIUMauthentik allows existing authenticated users to create arbitrary accountsEPSS 0.5%CVE-2023-51481CRITICALWordPress Local Delivery Drivers for WooCommerce plugin <= 1.9.0 - Unauthenticated Account Takeover vulnerabilityEPSS 0.5%CVE-2024-30542CRITICALWordPress WholesaleX plugin <= 1.3.2 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-51119CRITICALAn issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser componentsEPSS 0.5%CVE-2023-51476CRITICALWordPress WP MLM Unilevel plugin <= 4.0 - Unauthenticated Account Takeover vulnerabilityEPSS 0.5%CVE-2022-32907HIGHThis issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary coEPSS 0.5%CVE-2024-12398HIGHAn improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) anEPSS 0.5%CVE-2024-38770CRITICALWordPress Backup and Staging by WP Time Capsule plugin <= 1.22.20 - Authentication Bypass and Privilege Escalation VulnerabilityEPSS 0.5%CVE-2026-40172HIGHauthentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuserEPSS 0.5%CVE-2023-43845CRITICALAten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials EPSS 0.5%CVE-2020-13513HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2020-13515HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/EPSS 0.5%CVE-2022-41339HIGHIn Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.EPSS 0.5%