Weaknesses of type CWE-269

2,510 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-27301HIGHPrivilege Escalation Abusing installer in SupportAppEPSS 0.3%CVE-2025-50069HIGHVulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. EasiEPSS 0.3%CVE-2025-3438MEDIUMMStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege EscalationEPSS 0.3%CVE-2026-68821HIGHWindows Package Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-20308MEDIUMCisco IOS XE Software Web-Based Management Interface VulnerabilityEPSS 0.3%CVE-2023-50677HIGHAn issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cEPSS 0.3%CVE-2024-47853HIGHAn issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into MahEPSS 0.3%CVE-2025-6080HIGHWPGYM <= 67.7.0 - Missing Authorization to Admin Account CreationEPSS 0.3%CVE-2026-60342MEDIUMVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.3%CVE-2023-52107HIGHVulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect serviceEPSS 0.3%CVE-2025-12424CRITICALPrivilege Escalation through SUID-bit BinaryEPSS 0.3%CVE-2025-67793CRITICALAn issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permEPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2018-17954CRITICALcrowbar provision leaks admin password to all nodes in cleartextEPSS 0.3%CVE-2024-6240HIGHImproper privilege management vulnerability in Parallels DesktopEPSS 0.3%CVE-2023-46756—Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up wEPSS 0.3%CVE-2025-11168HIGHMementor Core <= 2.2.5 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2026-73714HIGHAuthenticated Sensitive Information Disclosure in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2026-16071MEDIUMKeycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundaryEPSS 0.3%CVE-2026-45801MEDIUMGLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)EPSS 0.3%