Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-48010MEDIUMShopware: Privilege escalation: non-admin user with user:create ACL can create admin accountsEPSS 0.5%CVE-2023-47629HIGHPrivilege escalation through email sign-up in datahubEPSS 0.5%CVE-2024-0003CRITICALA condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the arrayEPSS 0.5%CVE-2026-8176HIGHLatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password ResetEPSS 0.5%CVE-2022-48283CRITICALA piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnEPSS 0.5%CVE-2022-48284CRITICALA piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnEPSS 0.5%CVE-2022-42046HIGHwfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalationEPSS 0.5%CVE-2026-49176HIGHWindows WalletService Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2024-39206HIGHAn issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup dueEPSS 0.5%CVE-2025-66428HIGHAn issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.EPSS 0.5%CVE-2024-33223HIGHAn issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute EPSS 0.5%CVE-2024-28905HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-68561HIGHWekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow ruleEPSS 0.5%CVE-2022-35764HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-1606LOWIncorrect privilege assignment in M-Files ServerEPSS 0.5%CVE-2022-35763HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-35765HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-60369CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60373HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-61094HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.5%