Weaknesses of type CWE-269

2,488 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2017-0934—Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection ofEPSS 1.3%CVE-2020-8258—Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15EPSS 1.3%CVE-2026-8206CRITICALKirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'EPSS 1.3%CVE-2023-48902CRITICALAn issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car dEPSS 1.3%CVE-2017-0935—Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection EPSS 1.3%CVE-2020-8021MEDIUMunauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build ServiceEPSS 1.3%CVE-2022-43138CRITICALDolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.EPSS 1.3%CVE-2022-29218HIGHUnauthorized takeover for new versions of some platform-specific gemsEPSS 1.3%CVE-2021-27657HIGHMetasys Improper Privilege ManagementEPSS 1.2%CVE-2026-7467HIGHRead More & Accordion <= 3.5.7 - Privilege Escalation via importDataEPSS 1.2%CVE-2024-31141MEDIUMApache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProviderEPSS 1.2%CVE-2023-41954HIGHWordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerabilityEPSS 1.2%CVE-2021-28814HIGHImproper Access Control Vulnerability in HelpdeskEPSS 1.2%CVE-2017-0932—Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation EPSS 1.2%CVE-2021-31581HIGHAkkadian Provisioning Manager Engine (PME) Shell Escape via 'vi' editor interfaceEPSS 1.2%CVE-2022-20361MEDIUMIn btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth StaEPSS 1.2%CVE-2022-42735HIGHApache ShenYu Admin ultra viresEPSS 1.2%CVE-2020-7509—A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow aEPSS 1.2%CVE-2018-19635—CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.EPSS 1.2%CVE-2022-39395CRITICALVela Insecure DefaultsEPSS 1.2%