Weaknesses of type CWE-269

2,488 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2021-39168CRITICALTimelockController vulnerability in OpenZeppelin ContractsEPSS 1.6%CVE-2015-10139HIGHWPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege EscalationEPSS 1.6%CVE-2021-22801—A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configureEPSS 1.6%CVE-2025-15403CRITICALRegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_orderEPSS 1.6%CVE-2022-1654HIGHJupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege EscalationEPSS 1.6%CVE-2025-59247HIGHAzure PlayFab Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2023-49232CRITICALAn authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the passwEPSS 1.5%CVE-2020-24678HIGHPotential Privilege Escalation in Symphony PlusEPSS 1.5%CVE-2021-24602—HM Multiple Roles < 1.3 - Arbitrary Role ChangeEPSS 1.5%CVE-2026-46333HIGHptrace: slightly saner 'get_dumpable()' logicEPSS 1.5%CVE-2026-12394CRITICALMemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to AdministratorEPSS 1.5%CVE-2020-8223—A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than theyEPSS 1.5%CVE-2023-27645CRITICALAn issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQEPSS 1.5%CVE-2019-11280HIGHPrivilege escalation through the invitations serviceEPSS 1.5%CVE-2024-33775HIGHAn issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.EPSS 1.4%CVE-2022-31166HIGHXWiki.WebHome vulnerable to Improper Privilege Management in XWiki resolving groupsEPSS 1.4%CVE-2024-28247HIGHPihole Authenticated Arbitrary File Read with root privilegesEPSS 1.4%CVE-2020-36542HIGHDemokratian install3.php privileges managementEPSS 1.4%CVE-2024-8068MEDIUMPrivilege escalation to NetworkService Account accessEPSS 1.4%KEVCVE-2022-2317—Simple Membership < 4.1.3 - Unauthenticated Membership Privilege EscalationEPSS 1.4%