Weaknesses of type CWE-269

2,507 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-8719HIGHAI Engine 3.4.9 - Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer TokenEPSS 0.4%CVE-2026-75851CRITICALArcadeDB before 26.8.1 Authentication Bypass via Async CommandEPSS 0.4%CVE-2026-65603HIGHGrav Login Plugin 3.8.11 Privilege Escalation via Profile UpdateEPSS 0.4%CVE-2026-13741HIGHDigits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' ParameterEPSS 0.4%CVE-2026-57995HIGHphpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissionsEPSS 0.4%CVE-2026-67356HIGHArcadeDB before 26.7.3 Privilege Escalation via JavaScript TriggerEPSS 0.4%CVE-2026-13756HIGHWP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' ParameterEPSS 0.4%CVE-2026-6898HIGHWishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX actionEPSS 0.4%CVE-2026-12224HIGHDokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST EndpointEPSS 0.4%CVE-2026-41085HIGHThermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with EPSS 0.4%CVE-2025-71421HIGHUVdesk core-framework before 1.1.7 Privilege Escalation via editAgentEPSS 0.4%CVE-2024-8810HIGHPrivilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write accessEPSS 0.4%CVE-2025-36729HIGHRACOM M!DGE2 Privilege Escalation via SDK Testing EndpointEPSS 0.4%CVE-2026-19928MEDIUMOpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges managementEPSS 0.4%CVE-2026-2782HIGHPrivilege escalation in the Netmonitor componentEPSS 0.4%CVE-2026-8972HIGHPrivilege escalation in the WebRTC: Audio/Video componentEPSS 0.4%CVE-2025-21199MEDIUMAzure Agent Installer for Backup and Site Recovery Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-51392HIGHAn issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php componentEPSS 0.4%CVE-2024-33226CRITICALAn issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and eEPSS 0.4%CVE-2025-5931HIGHDokan Pro <= 4.0.5 - Authenticated (Vendor+) Privilege EscalationEPSS 0.4%