Weaknesses of type CWE-269

2,492 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-87155HIGHVulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are afEPSS 0.4%CVE-2026-61180HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality ManageEPSS 0.4%CVE-2026-62447HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affecteEPSS 0.4%CVE-2024-8246HIGHPost Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege EscalationEPSS 0.4%CVE-2024-21989HIGHPrivilege Escalation Vulnerability in ONTAP Select Deploy administration utilityEPSS 0.4%CVE-2026-75160CRITICALAn issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgiEPSS 0.4%CVE-2026-83328HIGHVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.4%CVE-2026-85569HIGHTutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request MisclassificationEPSS 0.4%CVE-2026-83325HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.4%CVE-2026-46716CRITICALNezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cronEPSS 0.4%CVE-2026-83176HIGHVulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported veEPSS 0.4%CVE-2026-83117HIGHVulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected arEPSS 0.4%CVE-2026-83273HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The suppoEPSS 0.4%CVE-2021-23876HIGHMcAfee Total Protection (MTP) Bypass Remote Procedure call vulnerabilityEPSS 0.4%CVE-2025-12882CRITICALClasifico Listing <= 2.0 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2024-52516LOWNextcloud Server's shares are not removed when user is limited to share with in their groups and being removed from one of themEPSS 0.4%CVE-2026-83322HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.4%CVE-2026-22043MEDIUMRustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account MintingEPSS 0.4%CVE-2025-15027CRITICALJAY Login & Register <= 2.6.03 - Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_userEPSS 0.4%CVE-2022-0144HIGHImproper Privilege Management in shelljs/shelljsEPSS 0.4%