Weaknesses of type CWE-269

2,510 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2020-7544—A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause prEPSS 0.3%CVE-2024-22795HIGHInsecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the RechecEPSS 0.3%CVE-2026-83241HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2025-25202MEDIUMAsh Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`EPSS 0.3%CVE-2026-5193MEDIUMEssential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_userEPSS 0.3%CVE-2025-6366HIGHEvent List <= 2.0.4 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2023-46810HIGHA local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute cEPSS 0.3%CVE-2013-10052HIGHZPanel zsudo Local Privilege EscalationEPSS 0.3%CVE-2025-45737MEDIUMAn issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafteEPSS 0.3%CVE-2026-14805HIGHConsulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAXEPSS 0.3%CVE-2025-54996HIGHOpenBao Root Namespace Operator May Elevate Token PrivilegesEPSS 0.3%CVE-2024-2003HIGHLocal Privilege Escalation in Quarantine of ESET products for WindowsEPSS 0.3%CVE-2025-59697HIGHEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.3%CVE-2026-100615HIGHCap-go capgo.app before 12.267.1 Privilege Escalation via API Key RotationEPSS 0.3%CVE-2026-73755MEDIUMPrivilege Escalation via Unauthorized Access to Sensitive Session InformationEPSS 0.3%CVE-2023-0664HIGHA flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's WinEPSS 0.3%CVE-2026-48210MEDIUMPossible information disclosure via External InterfaceEPSS 0.3%CVE-2023-23430LOW Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2025-8660MEDIUMPrivilege Escalation in Symantec PGP Encryption 11.0.1EPSS 0.3%CVE-2023-23428LOW Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%