Weaknesses of type CWE-269

2,508 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-61201CRITICALVulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported versEPSS 0.4%CVE-2026-61225HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versiEPSS 0.4%CVE-2026-18467CRITICALPaytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' ParameterEPSS 0.4%CVE-2020-6992—A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited,EPSS 0.4%CVE-2026-87231HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2026-62145HIGHLocal Privilege Escalation in Gaia PortalEPSS 0.4%CVE-2018-14787—In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalEPSS 0.4%CVE-2022-30739MEDIUMImproper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number withEPSS 0.4%CVE-2026-78999HIGHImproper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderEPSS 0.4%CVE-2026-18249HIGHIBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java RuntimeEPSS 0.4%CVE-2017-12728—An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-admiEPSS 0.4%CVE-2026-81818HIGHFlowintel Organization Administrator Can Reset Full Administrator Password and Escalate PrivilegesEPSS 0.4%CVE-2017-20112HIGHIVPN Client privileges managementEPSS 0.4%CVE-2026-46901CRITICALVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions thEPSS 0.4%CVE-2024-2228HIGHIdentityIQ Authorization of QuickLink Target Identities VulnerabilityEPSS 0.4%CVE-2024-41903HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts thEPSS 0.4%CVE-2026-44543HIGHLocal Path Provisioner: HelperPod Template InjectionEPSS 0.4%CVE-2026-62473HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.4%CVE-2025-30475HIGHDell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker wiEPSS 0.4%CVE-2026-60719CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.4%