Weaknesses of type CWE-269

2,508 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-13610HIGHKiviCare < 4.5.2 - Unauthenticated Privilege Escalation via RegistrationEPSS 0.4%CVE-2026-8980CRITICALPrivilege EscalationEPSS 0.4%CVE-2026-30269CRITICALImproper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privilegeEPSS 0.4%CVE-2026-12687HIGHProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group IDEPSS 0.4%CVE-2026-14333HIGHDemi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup DirectoryEPSS 0.4%CVE-2021-21430MEDIUMCreation of Temporary File in Directory with Insecure Permissions in auto-generated Java, Scala codeEPSS 0.4%CVE-2026-16534CRITICALImport and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV ImportEPSS 0.4%CVE-2025-11086HIGHAcademy LMS Pro <= 3.3.7 - Unauthenticated Privilege Escalation via Social Login AddonEPSS 0.4%CVE-2022-23743—Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weaEPSS 0.4%CVE-2025-3418HIGHWPC Admin Columns 2.0.6 - 2.1.0 - Authenticated (Subscriber+) Privilege Escalation via User Meta UpdateEPSS 0.4%CVE-2026-8952HIGHPrivilege escalation in the Application Update componentEPSS 0.4%CVE-2026-66399HIGHphpMyFAQ before 4.1.6 Privilege Escalation via Group MembershipEPSS 0.4%CVE-2026-50201MEDIUMSteeltoe's sensitive actuators (heapdump/env) only require Restricted permissionEPSS 0.4%CVE-2026-29647MEDIUMIn OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CEPSS 0.4%CVE-2024-21101LOWVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.33 aEPSS 0.4%CVE-2020-7280HIGHSymbolic Link vulnerability during DAT updateEPSS 0.4%CVE-2025-11457CRITICALEasyCommerce – AI-Powered, Blazing-Fast & Beautiful WordPress Ecommerce Plugin 0.9.0-beta2 - 1.8.2 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2021-31847HIGHImproper privilege management in repair process of MA for WindowsEPSS 0.4%CVE-2026-17956HIGHInappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insidEPSS 0.4%CVE-2026-17969HIGHInappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insideEPSS 0.4%