Weaknesses of type CWE-269

2,507 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-73711HIGHUnauthenticated Privilege Escalation allows Administrative Access in HPE Networking Fabric Composer APIEPSS 0.5%CVE-2025-37123HIGHAuthenticated Command Injection leads to Unauthorized Actions in CLI InterfaceEPSS 0.5%CVE-2026-42562HIGHPlainpad: Privilege Escalation via Writable Admin Field in Profile Update (Access Control)EPSS 0.5%CVE-2022-39422HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PriorEPSS 0.5%CVE-2025-8572CRITICALTruelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via RegistrationEPSS 0.5%CVE-2026-61203CRITICALVulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is EPSS 0.5%CVE-2020-13522HIGHAn exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packEPSS 0.5%CVE-2024-39302LOWSome bbb-record-core files installed with wrong file permissionEPSS 0.5%CVE-2026-74939HIGHPrivilege escalation in the DOM: Navigation componentEPSS 0.5%CVE-2026-74942HIGHPrivilege escalation in the Remote Settings Client componentEPSS 0.5%CVE-2026-74935HIGHPrivilege escalation in the DOM: Networking componentEPSS 0.5%CVE-2026-79411HIGHIncorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding oEPSS 0.5%CVE-2024-2005CRITICALSAML implementation allows privilege escalationEPSS 0.5%CVE-2026-18193HIGHIBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java RuntimeEPSS 0.5%CVE-2024-43121CRITICALWordPress HUSKY plugin <= 1.3.6.1 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-7960HIGHRockwell Automation Incorrect Privileges and Path Traversal Vulnerability in Pavilion8®EPSS 0.5%CVE-2026-45632CRITICALDokploy: Schedule Authorization Bypass Enables Host/Server Command ExecutionEPSS 0.5%CVE-2025-33067HIGHWindows Task Scheduler Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-6895HIGHWishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_export_settings' AJAX ActionEPSS 0.4%CVE-2026-9842HIGHBackstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role CapabilitiesEPSS 0.4%