Weaknesses of type CWE-269

2,509 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-3137HIGHImproper Privilege Management in uvdesk/community-skeletonEPSS 0.4%CVE-2022-32819HIGHA logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8EPSS 0.4%CVE-2025-59514HIGHMicrosoft Streaming Service Proxy Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-9966HIGHExecution with Unnecessary PrivilegesEPSS 0.4%CVE-2026-87068MEDIUMForminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form ImportEPSS 0.4%CVE-2026-83450HIGHVulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are EPSS 0.4%CVE-2026-57599MEDIUMThere is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attacEPSS 0.4%CVE-2026-83483HIGHVulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versionEPSS 0.4%CVE-2018-8841—In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prioEPSS 0.4%CVE-2026-19222MEDIUMForminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role BypassEPSS 0.4%CVE-2023-38292HIGHCertain software builds for the TCL 20XE Android device contain a vulnerable, pre-installed app with a package name of com.tct.gcs.hiddenmenEPSS 0.4%CVE-2026-87245HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2024-13376HIGHIndustrial <= 1.7.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options UpdateEPSS 0.4%CVE-2026-28976HIGHAn information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root prEPSS 0.4%CVE-2026-40009MEDIUMApache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditorEPSS 0.4%CVE-2025-32974CRITICALorg.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't consider TextAreas with default content typeEPSS 0.4%CVE-2024-5525HIGHImproper privilege management vulnerability in AstrotalksEPSS 0.4%CVE-2026-26010HIGHLeaky JWTs in OpenMetadata exposing highly-privileged bot usersEPSS 0.4%CVE-2026-23990MEDIUMFlux Operator Web UI Impersonation Bypass via Empty OIDC ClaimsEPSS 0.4%CVE-2024-46999HIGHUser Grant Deactivation not Working in ZitadelEPSS 0.4%