Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-1138HIGHTIBCO FTL Privilege EscalationEPSS 0.5%CVE-2023-36628HIGHPrivilege Escalation in VASAEPSS 0.5%CVE-2026-14960CRITICALCVE-2026-14960EPSS 0.5%CVE-2026-73305HIGHBudibase: Privilege escalation via public role assignment API missing app-level authorizationEPSS 0.5%CVE-2026-72886CRITICALDokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)EPSS 0.5%CVE-2025-37123HIGHAuthenticated Command Injection leads to Unauthorized Actions in CLI InterfaceEPSS 0.5%CVE-2025-8572CRITICALTruelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via RegistrationEPSS 0.5%CVE-2022-39422HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PriorEPSS 0.5%CVE-2026-61203CRITICALVulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is EPSS 0.5%CVE-2020-13522HIGHAn exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packEPSS 0.5%CVE-2024-39302LOWSome bbb-record-core files installed with wrong file permissionEPSS 0.5%CVE-2026-87246HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-46867HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). SupEPSS 0.5%CVE-2026-87244HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2024-2005CRITICALSAML implementation allows privilege escalationEPSS 0.5%CVE-2026-83440HIGHVulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are afEPSS 0.5%CVE-2026-87239HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-83442HIGHVulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are afEPSS 0.5%CVE-2026-46922HIGHVulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.5%CVE-2026-46970HIGHVulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.5%