Weaknesses of type CWE-269

2,508 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-42995HIGHVTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrativEPSS 0.4%CVE-2026-17751HIGHInappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside EPSS 0.4%CVE-2026-15369CRITICALCustom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API CheckoutEPSS 0.4%CVE-2021-22118—In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege esEPSS 0.4%CVE-2026-94048MEDIUMCodeAstro QR Code Attendance Management System UserController.php save privileges managementEPSS 0.4%CVE-2026-12165HIGHContest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' ParameterEPSS 0.4%CVE-2026-5373HIGHrunZero Platform superuser privilege escalationEPSS 0.4%CVE-2026-72537HIGHAuthentik Security authentik - Privilege EscalationEPSS 0.4%CVE-2026-86516MEDIUMelenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges managementEPSS 0.4%CVE-2025-7784MEDIUMOrg.keycloak/keycloak-services: privilege escalation in keycloak admin console (fgapv2 enabled)EPSS 0.4%CVE-2024-13835HIGHPost Meta Data Manager <= 1.4.4 - Authentciated (Admin+) Multisite Privilege EscalationEPSS 0.4%CVE-2026-87186CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-12289HIGHPrivilege escalation in the Graphics: WebRender componentEPSS 0.4%CVE-2026-36425MEDIUMAn issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the deviceEPSS 0.4%CVE-2026-12497HIGHProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role SelectionEPSS 0.4%CVE-2025-29924HIGHXWiki uses the wrong wiki reference in AuthorizationManagerEPSS 0.4%CVE-2023-43664MEDIUMEmployee without any access rights can list all installed modules in PrestashopEPSS 0.4%CVE-2018-19012—Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. VEPSS 0.4%CVE-2026-7327HIGHPrivilege escalation in Progress MarkLogic Server REST API document processingEPSS 0.4%CVE-2022-33646HIGHAzure Batch Node Agent Elevation of Privilege VulnerabilityEPSS 0.4%