Weaknesses of type CWE-269

2,510 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2023-25834MEDIUMBUG-000142922 Incomplete permission changes in specific cases.EPSS 0.3%CVE-2026-83292HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.3%CVE-2026-83489HIGHVulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding Batch Processes). EPSS 0.3%CVE-2026-83289HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). SupporEPSS 0.3%CVE-2026-83263HIGHVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.3%CVE-2025-5088HIGHArista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis SessionEPSS 0.3%CVE-2026-86406HIGHUser Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership PurchaseEPSS 0.3%CVE-2026-76396HIGHImproper Access Control through Scheduled Searches in Splunk AI ToolkitEPSS 0.3%CVE-2026-83257HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2026-83296HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versionsEPSS 0.3%CVE-2026-83295HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). SupporEPSS 0.3%CVE-2026-83272HIGHVulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and EPSS 0.3%CVE-2026-83451HIGHVulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.3%CVE-2026-83318HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are EPSS 0.3%CVE-2025-61152MEDIUMpython-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A maliEPSS 0.3%CVE-2026-83114HIGHVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectEPSS 0.3%CVE-2026-83262HIGHVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.3%CVE-2025-13851CRITICALBuyent Theme (with Buyent Classified Plugin) <= 1.0.7 - Unauthenticated Privilege Escalation via User RegistrationEPSS 0.3%CVE-2026-11423CRITICALPath Traversal in Altium Enterprise Server Collaboration Service Allows Privilege EscalationEPSS 0.3%CVE-2025-3438MEDIUMMStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege EscalationEPSS 0.3%