Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-26600ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer throuEPSS 6.3%CVE-2024-38014HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 6.3%KEVCVE-2024-24409HIGHPrivilege EscalationEPSS 6.2%CVE-2022-37706HIGHenlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library funEPSS 5.5%CVE-2019-25066MEDIUMajenti API privileges managementEPSS 5.4%CVE-2022-3405CRITICALCode execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affectEPSS 5.3%CVE-2002-0367HIGHsmss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which alEPSS 4.9%KEVCVE-2020-27654CRITICALImproper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitraryEPSS 4.7%CVE-2021-26697Apache Airflow: Lineage API endpoint for Experimental API missed authentication checkEPSS 4.6%CVE-2022-34699HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 4.4%CVE-2016-10010HIGHsshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local usEPSS 4.2%CVE-2021-34622CRITICALProfilePress 3.0 - 3.1.3 - Authenticated Privilege EscalationEPSS 4.1%CVE-2022-35761HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 4.0%CVE-2024-26169HIGHWindows Error Reporting Service Elevation of Privilege VulnerabilityEPSS 4.0%KEVCVE-2015-0192CRITICALUnspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 befoEPSS 4.0%CVE-2026-21533HIGHWindows Remote Desktop Services Elevation of Privilege VulnerabilityEPSS 3.9%KEVCVE-2014-125001HIGHCardo Systems Scala Rider Q3 Cardo-Updater api privileges managementEPSS 3.7%CVE-2024-24402CRITICALAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd compoEPSS 3.4%CVE-2023-37999CRITICALWordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerabilityEPSS 3.3%CVE-2023-0872HIGHROLE_REST can be used to escalate to ROLE_ADMIN via /rest/usersEPSS 3.3%