Weaknesses of type CWE-269

2,509 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-46935HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-46934HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-60943HIGHVulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versiEPSS 0.3%CVE-2026-60855HIGHVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectEPSS 0.3%CVE-2026-87139HIGHVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.3%CVE-2026-60619HIGHVulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base). The sEPSS 0.3%CVE-2026-61188HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The sEPSS 0.3%CVE-2026-86554MEDIUMEmail enumeration and account ID leakage vulnerabilities in ZTE SmartLife APPEPSS 0.3%CVE-2026-9918CRITICALInappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escEPSS 0.3%CVE-2024-21985HIGHPrivilege Escalation Vulnerability in ONTAP 9 EPSS 0.3%CVE-2026-12470HIGHCMP <= 4.1.17 - Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX ActionEPSS 0.3%CVE-2026-17868HIGHInsufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation viaEPSS 0.3%CVE-2025-8218HIGHReal Spaces - WordPress Properties Directory Theme <= 3.5 - Authenticated (Subscriber+) Privilege Escalation to Administrator via 'change_role_member'EPSS 0.3%CVE-2023-4834MEDIUMIn Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implementEPSS 0.3%CVE-2023-47715MEDIUMIBM Storage Protect Plus Server improper access controlEPSS 0.3%CVE-2026-72631MEDIUMImproper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API KeysEPSS 0.3%CVE-2022-43997HIGHIncorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficEPSS 0.3%CVE-2023-39520MEDIUMCryptomator vulnerable to Local Elevation of PrivilegesEPSS 0.3%CVE-2024-55631HIGHAn engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installationsEPSS 0.3%CVE-2024-45919MEDIUMA security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the RequeEPSS 0.3%