Weaknesses of type CWE-269

2,510 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-45919MEDIUMA security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the RequeEPSS 0.3%CVE-2026-72631MEDIUMImproper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API KeysEPSS 0.3%CVE-2025-22220MEDIUMVMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220)EPSS 0.3%CVE-2025-63909HIGHIncorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allowsEPSS 0.3%CVE-2024-30473MEDIUMDell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could pEPSS 0.3%CVE-2026-49176HIGHWindows WalletService Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-77203HIGHGroups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' ShortcodeEPSS 0.3%CVE-2026-69414HIGHMicrosoft Defender Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2020-11846HIGHImproper handling of token allows access to restricted resource in Privileged Access ManagerEPSS 0.3%CVE-2025-11923HIGHLifterLMS – WP LMS for eLearning, Online Courses, & Quizzes - Various Versions - Authenticated (Student+) Privilege EscalationEPSS 0.3%CVE-2024-45297MEDIUMPrevent topic list filtering by hidden tags for unauthorized users in DiscourseEPSS 0.3%CVE-2026-79226HIGHImproper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social eEPSS 0.3%CVE-2026-46804HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that EPSS 0.3%CVE-2026-34496HIGHvictor Web - Priviledge EscalationEPSS 0.3%CVE-2026-18550CRITICALNokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' ParameterEPSS 0.3%CVE-2025-59705MEDIUMEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a PhysiEPSS 0.3%CVE-2023-32713HIGHLocal Privilege Escalation via the ‘streamfwd’ program in Splunk App for StreamEPSS 0.3%CVE-2026-65835MEDIUMCapsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)EPSS 0.3%CVE-2025-8107MEDIUMIn OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executiEPSS 0.3%CVE-2024-1575MEDIUMThe improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an autheEPSS 0.3%