Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2020-13512HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2023-43845CRITICALAten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials EPSS 0.5%CVE-2024-25847CRITICALSQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6EPSS 0.5%CVE-2023-50726MEDIUMUsers with `create` but not `override` privileges can perform local sync in argo-cdEPSS 0.5%CVE-2020-13517MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0. A specially craftedEPSS 0.5%CVE-2022-4264MEDIUMIncorrect privilege assignment in M-Files Web ServerEPSS 0.5%CVE-2024-4545HIGHEDB Postgres Advanced Server (EPAS) authenticated file read permissions bypass using edbldrEPSS 0.5%CVE-2025-4315HIGHCubeWP – All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.5%CVE-2026-33509HIGHpyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script ConfigurationEPSS 0.5%CVE-2022-4270LOWIncorrect privilege assignment in M-Files Web ServerEPSS 0.5%CVE-2024-44893CRITICALAn issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET requeEPSS 0.5%CVE-2020-35517—A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest usEPSS 0.5%CVE-2022-25311HIGHA vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All EPSS 0.5%CVE-2023-47782HIGHWordPress Thrive Theme Builder theme < 3.24.0 - Authenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-47409HIGHpraisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}EPSS 0.5%CVE-2026-47412HIGHpraisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}EPSS 0.5%CVE-2024-7291HIGHJetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege EscalationEPSS 0.5%CVE-2022-42855HIGHA logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOSEPSS 0.5%CVE-2023-48319MEDIUMWordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-16904HIGHIBM i is Affected By improper privilege management in Navigator for iEPSS 0.5%