Weaknesses of type CWE-269

2,490 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-7960HIGHRockwell Automation Incorrect Privileges and Path Traversal Vulnerability in Pavilion8®EPSS 0.5%CVE-2024-43121CRITICALWordPress HUSKY plugin <= 1.3.6.1 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2025-33067HIGHWindows Task Scheduler Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-9842HIGHBackstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role CapabilitiesEPSS 0.4%CVE-2022-46327CRITICALSome smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in sEPSS 0.4%CVE-2021-46894—Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalatioEPSS 0.4%CVE-2025-21360HIGHMicrosoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-45373HIGHDover Fueling Solutions ProGauge MAGLINK LX CONSOLE Improper Privilege ManagementEPSS 0.4%CVE-2022-34706HIGHWindows Local Security Authority (LSA) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-8263MEDIUMAn improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use ofEPSS 0.4%CVE-2024-10203HIGHAgent Arbitrary File DeletionEPSS 0.4%CVE-2024-32960HIGHWordPress Booking Ultra Pro plugin 1.1.12 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2026-86553HIGHA password reset vulnerability in ZTE SmartLife APPEPSS 0.4%CVE-2025-34251HIGHTesla Telematics Control Unit (TCU) < v2025.14 Authentication BypassEPSS 0.4%CVE-2024-51324LOWAn issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (BriEPSS 0.4%CVE-2023-29056MEDIUMA valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC mustEPSS 0.4%CVE-2026-31852CRITICALJellyfin Possible Organization/Secret Compromise from dangerous CI implementationEPSS 0.4%CVE-2025-55187CRITICALIn DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.EPSS 0.4%CVE-2025-2237CRITICALWP RealEstate <= 1.6.26 - Unauthenticated Privilege Escalation via 'process_register'EPSS 0.4%CVE-2022-29614—SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22EPSS 0.4%