Weaknesses of type CWE-269

2,488 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-34187CRITICALIlevia EVE X1/X5 Server 4.7.18.0.eden Reverse RootshellEPSS 3.2%CVE-2014-9193Innominate mGuard Improper Privilege ManagementEPSS 3.1%CVE-2024-34082HIGHGrav Arbitrary File Read to Account TakeoverEPSS 3.0%CVE-2026-25643CRITICALFrigate Affected by Authenticated Remote Command Execution (RCE) and Container EscapeEPSS 2.9%CVE-2024-6624CRITICALJSON API User <= 3.9.3 - Unauthenticated Privilege EscalationEPSS 2.9%CVE-2019-7394A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8EPSS 2.8%CVE-2021-25337MEDIUMImproper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to readEPSS 2.8%KEVCVE-2023-26540CRITICALWordPress Houzez theme <= 2.7.1 - Privilege EscalationEPSS 2.7%CVE-2023-26009CRITICALWordPress Houzez Login Register plugin <= 2.6.3 - Privilege EscalationEPSS 2.7%CVE-2020-8269An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixEPSS 2.7%CVE-2020-8283An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versionEPSS 2.7%CVE-2023-35674HIGHIn onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead tEPSS 2.6%KEVCVE-2023-29350HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 2.6%CVE-2022-1770CRITICALImproper Privilege Management in polonel/trudeskEPSS 2.5%CVE-2020-15149CRITICALAccount takeover in NodeBBEPSS 2.4%CVE-2022-24812HIGHFGAC API Key privilege escalation in GrafanaEPSS 2.4%CVE-2024-21324HIGHMicrosoft Defender for IoT Elevation of Privilege VulnerabilityEPSS 2.3%CVE-2023-39335A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impEPSS 2.3%CVE-2025-4334CRITICALSimple User Registration <= 6.3 - Unauthenticated Privilege EscalationEPSS 2.3%CVE-2017-0358HIGHntfs-3g: Modprobe influence vulnerability via environment variablesEPSS 2.2%