Weaknesses of type CWE-269

2,509 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-13619CRITICALFlex Store Users <= 1.1.0 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2025-8900CRITICALDoccure Core < 1.5.4 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2025-13542CRITICALDesignThemes LMS <= 1.0.4 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2026-14250MEDIUMThemehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' ParameterEPSS 0.4%CVE-2024-22278MEDIUMHarbor fails to validate the user permissions when updating project configurationsEPSS 0.4%CVE-2025-47420HIGHUser Permissions on Network APIEPSS 0.4%CVE-2024-46916HIGHDiebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before theEPSS 0.4%CVE-2026-73723HIGHAuthenticated Privilege Escalation Leading to Unauthorized State Changes in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.4%CVE-2026-3621HIGHIBM WebSphere Application Server Liberty is affected by identity spoofingEPSS 0.4%CVE-2026-17950HIGHInappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary cEPSS 0.4%CVE-2024-37560HIGHWordPress WP User Switch plugin <= 1.1.0 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2022-0556HIGHA local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) EPSS 0.4%CVE-2023-52209HIGHWordPress WPForms User Registration plugin <= 2.1.0 - Authenticated Privilege Escalation vulnerabilityEPSS 0.4%CVE-2026-85514MEDIUMStackStorm st2 API Key auth.py privileges managementEPSS 0.4%CVE-2026-19005MEDIUMnanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges managementEPSS 0.4%CVE-2026-19007MEDIUMmf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges managementEPSS 0.4%CVE-2024-11218HIGHPodman: buildah: container breakout by using --jobs=2 and a race condition when building a malicious containerfileEPSS 0.4%CVE-2026-73788MEDIUMPrivilege Escalation in ClearPass OnGuard AgentEPSS 0.4%CVE-2025-53105HIGHGLPI permits unauthorized rules execution orderEPSS 0.4%CVE-2026-66782MEDIUMSubmariner-operator: operator clusterrole grants cluster-wide create/update on all configmapsEPSS 0.4%