Weaknesses of type CWE-269

2,508 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-54652HIGHFrigate viewer can read logs exposing admin and camera credentialsEPSS 0.4%CVE-2026-56225HIGHCapgo - Authorization Bypass in API Key Management via App-Limited KeysEPSS 0.4%CVE-2024-42774HIGHAn Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unaEPSS 0.4%CVE-2024-47000HIGHService Users Deactivation not Working in ZitadelEPSS 0.4%CVE-2024-23253HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a useEPSS 0.4%CVE-2026-44231CRITICALRT: Privilege escalation and information disclosure via REST 2.0 user collection endpointEPSS 0.4%CVE-1999-0084HIGHCertain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.EPSS 0.4%CVE-2024-5909MEDIUMCortex XDR Agent: Local Windows User Can Disable the AgentEPSS 0.4%CVE-2025-59790MEDIUMApache Kvrocks: RESET command grants admin privilegesEPSS 0.4%CVE-2026-5141HIGHImproper Access Control in TUBITAK BILGEM's Pardus Software CenterEPSS 0.4%CVE-2025-23208HIGHIdP group membership revocation ignored in zotEPSS 0.4%CVE-2024-36046CRITICALInfoblox NIOS through 8.6.4 executes with more privileges than required.EPSS 0.4%CVE-2023-44106—API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perforEPSS 0.4%CVE-2023-44105—Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cEPSS 0.4%CVE-2025-6994CRITICALReveal Listing <= 3.3 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2026-9999HIGHInappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inEPSS 0.4%CVE-2012-10022HIGHKloxo <= 6.1.12 Local Privilege EscalationEPSS 0.4%CVE-2018-14828—Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files EPSS 0.4%CVE-2026-16764MEDIUMOWASP DefectDojo API/Web serializers.py UserSerializer privileges managementEPSS 0.4%CVE-2026-60941HIGHVulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versiEPSS 0.4%