Weaknesses of type CWE-269

2,507 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-22043MEDIUMRustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account MintingEPSS 0.4%CVE-2025-15027CRITICALJAY Login & Register <= 2.6.03 - Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_userEPSS 0.4%CVE-2026-78174CRITICALWatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic LogsEPSS 0.4%CVE-2026-17553HIGHShopping Cart & eCommerce Store <= 5.9.3 - Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX ActionEPSS 0.4%CVE-2026-94047MEDIUMsamanhappy MCPHub Template Import Endpoint templateService.ts importTemplate privileges managementEPSS 0.4%CVE-2022-0144HIGHImproper Privilege Management in shelljs/shelljsEPSS 0.4%CVE-2024-11951CRITICALHomey Login Register <= 2.4.0 - Unauthenticated Privilege Escalation in homey_registerEPSS 0.4%CVE-2026-53515HIGHBetter Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/ssoEPSS 0.4%CVE-2024-12281CRITICALHomey <= 2.4.2 - Unauthenticated Privilege Escalation in homey_save_profileEPSS 0.4%CVE-2026-60567CRITICALVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are afEPSS 0.4%CVE-2024-13058MEDIUMAuthenticated, non-admin users can create storage pools via the sifi APIEPSS 0.4%CVE-2025-3852HIGHWPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account TakeoverEPSS 0.4%CVE-2026-85513MEDIUMStackStorm st2 NoOp RBAC backend actionexecutions.py privileges managementEPSS 0.4%CVE-2026-76253HIGHPrivilege Escalation through Scheduled Search Alert Action Configuration in Splunk EnterpriseEPSS 0.4%CVE-2023-41312—Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated aEPSS 0.4%CVE-2024-13343HIGHWooCommerce Customers Manager <= 31.3 - Missing Authorization to Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2024-3057CRITICALA flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.EPSS 0.4%CVE-2022-4808MEDIUMImproper Privilege Management in usememos/memosEPSS 0.4%CVE-2026-77968HIGHHawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to operator serviceaccountEPSS 0.4%CVE-2023-46771HIGHSecurity vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%