Weaknesses of type CWE-269

2,509 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-83258HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-83245HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-83299HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). The sEPSS 0.4%CVE-2026-83286HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.4%CVE-2026-82842HIGHSAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account MatchingEPSS 0.4%CVE-2026-83246HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-53645HIGHFOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalationEPSS 0.4%CVE-2020-11640HIGHElevation of PrivilegeEPSS 0.4%CVE-2026-9327MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.4%CVE-2026-94381HIGHMISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via updateLoginTimeEPSS 0.4%CVE-2023-41743HIGHLocal privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber ProtectEPSS 0.4%CVE-2026-43978HIGHwger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managersEPSS 0.4%CVE-2026-88891HIGHOpenPanel Read-Only Access Level Enforcement Bypass via MutationsEPSS 0.4%CVE-2025-8899HIGHPaid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.3.20 - Authenticated (Author+) Privilege EscalationEPSS 0.4%CVE-2026-24894HIGHFrankenPHP leaks session data between requests in worker modeEPSS 0.4%CVE-2025-3101HIGHConfigurator Theme Core <= 1.4.7 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2021-23877MEDIUMMcAfee Total Protection (MTP) - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-28237HIGHAn issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON EPSS 0.4%CVE-2024-42798HIGHAn Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara MusiEPSS 0.4%CVE-2026-92033HIGHPrivilege escalation in Firefox for AndroidEPSS 0.4%