Weaknesses of type CWE-269

2,492 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-36046CRITICALInfoblox NIOS through 8.6.4 executes with more privileges than required.EPSS 0.4%CVE-2026-94047MEDIUMsamanhappy MCPHub Template Import Endpoint templateService.ts importTemplate privileges managementEPSS 0.4%CVE-2025-6994CRITICALReveal Listing <= 3.3 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2023-44106—API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perforEPSS 0.4%CVE-2023-44105—Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cEPSS 0.4%CVE-2025-23208HIGHIdP group membership revocation ignored in zotEPSS 0.4%CVE-2022-23743—Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weaEPSS 0.4%CVE-2018-14828—Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files EPSS 0.4%CVE-2026-60941HIGHVulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versiEPSS 0.4%CVE-2026-16764MEDIUMOWASP DefectDojo API/Web serializers.py UserSerializer privileges managementEPSS 0.4%CVE-2012-10022HIGHKloxo <= 6.1.12 Local Privilege EscalationEPSS 0.4%CVE-2026-5144HIGHBuddyPress Groupblog <= 1.9.3 - Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOREPSS 0.4%CVE-2021-21430MEDIUMCreation of Temporary File in Directory with Insecure Permissions in auto-generated Java, Scala codeEPSS 0.4%CVE-2026-60175HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0EPSS 0.4%CVE-2025-11086HIGHAcademy LMS Pro <= 3.3.7 - Unauthenticated Privilege Escalation via Social Login AddonEPSS 0.4%CVE-2026-46885HIGHVulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 17.0-26EPSS 0.4%CVE-2026-46921HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.4%CVE-2026-46852CRITICALVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported vEPSS 0.4%CVE-2026-70928HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-87224HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%