Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-61094HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.5%CVE-2024-29975MEDIUM** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versiEPSS 0.5%CVE-2026-60439HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-22645HIGHkubewarden: Excessive permissions for kubewarden-controller-manager-cluster-roleEPSS 0.5%CVE-2026-61246HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-28436MEDIUMNon-interactive Tailscale SSH sessions on FreeBSD may use the effective group ID of the tailscaled processEPSS 0.5%CVE-2025-54594CRITICALreact-native-bottom-tabs: Arbitrary code execution in GitHub Actions canary workflow leads to secret exfiltrationEPSS 0.5%CVE-2026-42609HIGHGrav: Administrative Account Disruption and Privilege De-escalation via User Overwrite LogicEPSS 0.5%CVE-2026-83112HIGHVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported verEPSS 0.5%CVE-2026-81445HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privilegedEPSS 0.5%CVE-2026-83344HIGHVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table). SupportEPSS 0.5%CVE-2026-83298HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). The supported version that is affeEPSS 0.5%CVE-2026-83195HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.5%CVE-2026-17751HIGHInappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside EPSS 0.5%CVE-2026-83260CRITICALVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX). The supported version that is affected isEPSS 0.5%CVE-2020-13776MEDIUMsystemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated byEPSS 0.5%CVE-2026-44787HIGHDiscourse: Signup-time primary_group_id assignment grants whisperer accessEPSS 0.5%CVE-2026-78999HIGHImproper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderEPSS 0.5%CVE-2023-20598HIGH An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gainEPSS 0.5%CVE-2026-56245HIGHSupabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning via record_build_time RPCEPSS 0.5%