Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2022-45451HIGHLocal privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber ProtectEPSS 0.5%CVE-2024-33569HIGHWordPress Instant Images plugin <= 6.1.0 - Arbitrary Option Update to Privilege Escalation vulnerabilityEPSS 0.5%CVE-2023-5978—Incorrect libcap_net limitation list manipulationEPSS 0.5%CVE-2026-18432CRITICALFrontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' ParameterEPSS 0.5%CVE-2022-3068MEDIUMImproper Privilege Management in octoprint/octoprintEPSS 0.5%CVE-2025-53942HIGHauthentik has an insufficient check for account active status during OAuth/SAML authenticationEPSS 0.5%CVE-2026-60566CRITICALVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are afEPSS 0.5%CVE-2026-18713HIGHIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.5%CVE-2026-61154CRITICALVulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version EPSS 0.5%CVE-2026-60532CRITICALVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported EPSS 0.5%CVE-2025-15030CRITICALUser Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-17145CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2024-55954HIGHOpenObserve Improper Authorization Allows Admin User to Remove Root UserEPSS 0.5%CVE-2024-37665HIGHAn access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator via a crafted POST reqEPSS 0.5%CVE-2025-40538CRITICALSolarWinds Serv-U Broken Access Control Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-1295HIGHTemplines Elementor Helper Core <= 2.7 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.5%CVE-2022-37002HIGHThe SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applicationsEPSS 0.5%CVE-2022-35921LOWUser preference to prevent private discussions not respected in fof/byobuEPSS 0.5%CVE-2026-4880CRITICALBarcode Scanner (+Mobile App) <= 1.11.0 - Unauthenticated Privilege Escalation via Insecure Token AuthenticationEPSS 0.5%CVE-2026-76801HIGHFireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege EscalationEPSS 0.5%