Weaknesses of type CWE-269

2,498 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-72863CRITICALDokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker hostEPSS 0.6%CVE-2023-47132CRITICALAn issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.EPSS 0.6%CVE-2019-25068MEDIUMAxios Italia Axios RE Connection REDefault.aspx privileges managementEPSS 0.6%CVE-2024-0353HIGHLocal privilege escalation in Windows productsEPSS 0.6%CVE-2026-76713HIGHAuthenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.6%CVE-2026-12981HIGHCAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password ResetEPSS 0.6%CVE-2024-36077HIGHQlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attackEPSS 0.6%CVE-2026-16337CRITICALImproper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms EPSS 0.5%CVE-2024-25842HIGHAn issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop EPSS 0.5%CVE-2025-21287HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-2931HIGHAmelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password ChangeEPSS 0.5%CVE-2024-57778HIGHAn issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from stEPSS 0.5%CVE-2023-41309—Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availabilitEPSS 0.5%CVE-2026-60372CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60366CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60367CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2025-29033HIGHAn issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parEPSS 0.5%CVE-2023-50890HIGHWordPress Ultimate Addons for Elementor plugin <= 1.36.20 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2023-51398HIGHWordPress Ultimate Addons for Beaver Builder Premium plugin <= 1.35.14 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2025-22937CRITICALAn issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.EPSS 0.5%