Weaknesses of type CWE-269

2,509 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-56239HIGHCapgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overageEPSS 0.3%CVE-2026-93901HIGHOptima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role AssignmentEPSS 0.3%CVE-2026-77698MEDIUMPrivilege EscalationEPSS 0.3%CVE-2026-23896HIGHimmich API Key Privilege Escalation vulnerabilityEPSS 0.3%CVE-2023-43663MEDIUMImproper Privilege Management in PrestashopEPSS 0.3%CVE-2025-43333HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to gain root priviEPSS 0.3%CVE-2023-30601HIGHApache Cassandra: Privilege escalation when enabling FQL/Audit logsEPSS 0.3%CVE-2023-41036HIGHMacvim's Insecure Usage of IPC MechanismsEPSS 0.3%CVE-2025-70887HIGHAn issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py componeEPSS 0.3%CVE-2026-60492HIGHVulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundation). The supported EPSS 0.3%CVE-2023-23412HIGHWindows Accounts Picture Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-3513HIGHRazerCentralService Unsafe Deserialization Escalation of PrivilegeEPSS 0.3%CVE-2023-53908HIGHHiSecOS 04.0.01 Privilege Escalation via User Role ModificationEPSS 0.3%CVE-2026-1010HIGHStored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege EscalationEPSS 0.3%CVE-2026-56212MEDIUMCapgo - Improper 2FA Enforcement Logic via Team Security SettingsEPSS 0.3%CVE-2020-3393MEDIUMCisco IOS XE Software IOx Application Hosting Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-15630CRITICALCVE-2026-15630EPSS 0.3%CVE-2021-23891HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.3%CVE-2023-23427MEDIUM Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2022-24927MEDIUMImproper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files withoEPSS 0.3%