Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2019-15789HIGHMicrok8s Privilege Escalation VulnerabilityEPSS 0.5%CVE-2024-33567CRITICALWordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.5.3 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-31290CRITICALWordPress Demo My WordPress plugin <= 1.0.9.1 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-32511CRITICALWordPress Simple Registration for WooCommerce plugin <= 1.5.6 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-90523MEDIUMjaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges managementEPSS 0.5%CVE-2026-9810CRITICALAI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuthEPSS 0.5%CVE-2026-73293HIGHSemaphore UI: Manager-to-owner privilege escalation via custom-role slug collisionEPSS 0.5%CVE-2026-14719MEDIUMSourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges managementEPSS 0.5%CVE-2026-7284CRITICALEasy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_handle_registerEPSS 0.5%CVE-2024-22774HIGHAn issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exEPSS 0.5%CVE-2026-75166HIGHInsecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/EPSS 0.5%CVE-2025-6254CRITICALDoctreat Core <= 1.6.8 - Unauthenticated Privilege EscalationEPSS 0.5%CVE-2026-92957CRITICALvm2 before 3.11.7 Authentication Bypass via node: PrefixEPSS 0.5%CVE-2025-64338MEDIUMClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection NameEPSS 0.5%CVE-2026-76677HIGHAuthorization Bypass Leading to Privilege Escalation in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2025-25962CRITICALAn issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition funcEPSS 0.5%CVE-2024-28904HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2020-13509MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specialEPSS 0.5%CVE-2023-30617MEDIUMLeverage the kruise-daemon pod to list all secrets in the entire clusterEPSS 0.5%CVE-2024-48730MEDIUMThe default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions on the authenticatiEPSS 0.5%