Weaknesses of type CWE-269

2,509 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-3105HIGHVehica Core <= 1.0.97 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2026-77697MEDIUMPrivilege EscalationEPSS 0.4%CVE-2025-28400MEDIUMAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit methodEPSS 0.4%CVE-2026-85640MEDIUMPrivilege EscalationEPSS 0.4%CVE-2026-1993HIGHExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings UpdateEPSS 0.4%CVE-2026-19996MEDIUMWebkul Bagisto Backend Customer Behavior Data Endpoint customers privileges managementEPSS 0.4%CVE-2020-13510MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specialEPSS 0.4%CVE-2024-21121MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PrioEPSS 0.4%CVE-2024-41797MEDIUMA vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All EPSS 0.4%CVE-2023-23629MEDIUMMetabase subject to Improper Privilege ManagementEPSS 0.4%CVE-2026-87958HIGHIBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditionsEPSS 0.4%CVE-2023-2679MEDIUMData leakage in Adobe connector for SPE edition of SLMEPSS 0.4%CVE-2026-81442HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged EPSS 0.4%CVE-2022-48286HIGHThe multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect datEPSS 0.4%CVE-2025-6758CRITICALReal Spaces - WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator via 'imic_agent_register'EPSS 0.4%CVE-2025-3761HIGHMy Tickets – Accessible Event Ticketing <= 2.0.16 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2024-1973HIGHElevation of privileges vulnerabilityEPSS 0.4%CVE-2026-17645CRITICALIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.4%CVE-2022-48515—Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.4%CVE-2026-61237CRITICALVulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supportEPSS 0.4%