Weaknesses of type CWE-269

2,509 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-88817HIGHPrivilege escalation via legacy access group creation endpointEPSS 0.4%CVE-2026-45043CRITICALRustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including RootEPSS 0.4%CVE-2022-3419MEDIUMAutomatic User Roles Switcher < 1.1.2 - Subscriber+ Privilege EscalationEPSS 0.4%CVE-2021-21428CRITICALCreation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generatorEPSS 0.4%CVE-2023-52116HIGHPermission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service EPSS 0.4%CVE-2023-52716HIGHVulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vEPSS 0.4%CVE-2023-52105HIGHThe nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.EPSS 0.4%CVE-2024-3388MEDIUMPAN-OS: User Impersonation in GlobalProtect SSL VPNEPSS 0.3%CVE-2024-30150MEDIUMAn unauthenticated privilege escalation vulnerability affects HCL MyCloudEPSS 0.3%CVE-2025-13764CRITICALWP CarDealer <= 1.2.16 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2025-28401MEDIUMAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameterEPSS 0.3%CVE-2025-13559CRITICALEduKart Pro <= 1.0.3 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2024-27442HIGHAn issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executedEPSS 0.3%CVE-2025-13540CRITICALTiare Membership <= 1.2 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2025-13538CRITICALFindAll Listing <= 1.0.5 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2025-13675CRITICALTiger <= 101.2.1 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2022-39182MEDIUMH C Mingham-Smith Ltd - Tardis 2000 Privilege escalationEPSS 0.3%CVE-2026-23477HIGHRocket.Chat Unauthorized Access to OAuth App DetailsEPSS 0.3%CVE-2026-90487MEDIUMXuxueli xxl-job JobGroupController.java privileges managementEPSS 0.3%CVE-2026-90501MEDIUMlenve vhr HrMapper.xml HrInfoController.updateHr privileges managementEPSS 0.3%