Weaknesses of type CWE-269

2,507 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-79090CRITICALImproper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to byEPSS 0.4%CVE-2025-67727MEDIUMParse Server GitHub CI workflow vulnerable to RCE through Improper Privilege ManagementEPSS 0.4%CVE-2026-87187HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2024-39633HIGHWordPress PowerPack for Beaver Builder plugin <= 2.33.0 - Contributor+ Privilege Escalation vulnerabilityEPSS 0.4%CVE-2024-37107HIGHWordPress WishList Member X plugin < 3.26.7 - Authenticated Privilege Escalation vulnerabilityEPSS 0.4%CVE-2026-45790HIGHDokploy: Invitation Role Escalation Allows Organization TakeoverEPSS 0.4%CVE-2023-32194HIGHRancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'EPSS 0.4%CVE-2024-4988HIGHImproper permission control in com.transsion.videocallenhancerEPSS 0.4%CVE-2026-32181MEDIUMConnected User Experiences and Telemetry Service Denial of Service VulnerabilityEPSS 0.4%CVE-2023-41301—Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnoEPSS 0.4%CVE-2026-83331HIGHVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.4%CVE-2026-83315HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.4%CVE-2026-83479HIGHVulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.4%CVE-2026-83301HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service Administration UI). TEPSS 0.4%CVE-2026-47744CRITICALShopper: Authorization bypass and RBAC privilege escalation in team settingsEPSS 0.4%CVE-2026-88904HIGHPuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege EscalationEPSS 0.4%CVE-2026-83306HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supported versions that EPSS 0.4%CVE-2026-47870HIGHVMware Avi Load Balancer Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-83119HIGHVulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.4%CVE-2026-83271HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0EPSS 0.4%