Weaknesses of type CWE-269

2,508 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-83329HIGHVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.4%CVE-2026-83315HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.4%CVE-2026-83348HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0EPSS 0.4%CVE-2026-83338HIGHVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported vEPSS 0.4%CVE-2026-12525HIGHRedux Framework < 4.5.13 - Subscriber+ Privilege Escalation to AdministratorEPSS 0.4%CVE-2026-83423HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affEPSS 0.4%CVE-2026-83454HIGHVulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). SuppEPSS 0.4%CVE-2026-8970HIGHPrivilege escalation in the Security componentEPSS 0.4%CVE-2026-24059MEDIUMGitea runner registration-token GET endpoint performs a write under a read-only token scopeEPSS 0.4%CVE-2026-74952HIGHPrivilege escalation in the Application Update componentEPSS 0.4%CVE-2026-74955HIGHPrivilege escalation in the Request Handling componentEPSS 0.4%CVE-2026-6769HIGHPrivilege escalation in the Debugger componentEPSS 0.4%CVE-2026-74950HIGHPrivilege escalation in the Downloads API componentEPSS 0.4%CVE-2025-52289HIGHA Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafEPSS 0.4%CVE-2026-8957HIGHPrivilege escalation in the Enterprise Policies componentEPSS 0.4%CVE-2026-6761HIGHPrivilege escalation in the Networking componentEPSS 0.4%CVE-2026-8955HIGHPrivilege escalation in the DOM: Workers componentEPSS 0.4%CVE-2026-47407CRITICALPraisonAI Platform has a cross-workspace IDOR + member-role privilege escalationEPSS 0.4%CVE-2026-53444HIGHWekan: Missing authorization on OIDC Meteor methods allows privilege escalation to adminEPSS 0.4%CVE-2025-5954CRITICALService Finder SMS System <= 2.0.0 - Unauthenticated Privilege EscalationEPSS 0.4%