Weaknesses of type CWE-269

2,510 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-9471MEDIUMPAN-OS: Privilege Escalation (PE) Vulnerability in XML APIEPSS 0.3%CVE-2020-26191HIGHDell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the PEPSS 0.3%CVE-2020-7310MEDIUMPrivilege Escalation vulnerability in McAfee Total Protection (MTP) trial installerEPSS 0.3%CVE-2026-44119MEDIUMApache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modulesEPSS 0.3%CVE-2025-53026MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.3%CVE-2026-9892HIGHInappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the rEPSS 0.3%CVE-2026-17816HIGHInsufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2022-24077—Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.EPSS 0.3%CVE-2026-86746HIGHSnipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot ReplayEPSS 0.3%CVE-2025-53025MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.3%CVE-2021-23880MEDIUMImproper Access Control in the ENS installerEPSS 0.3%CVE-2026-77699MEDIUMPrivilege EscalationEPSS 0.3%CVE-2023-41053LOWRedis SORT_RO may bypass ACL configurationEPSS 0.3%CVE-2022-32781MEDIUMThis issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security UpdateEPSS 0.3%CVE-2026-12878HIGHIn affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.EPSS 0.3%CVE-2024-46989LOWMultiple caveats on resources of the same type can result in no permission when permission is expectedEPSS 0.3%CVE-2019-3588MEDIUMUsing VSE to bypass Windows Credentials on Lock screenEPSS 0.3%CVE-2024-52336HIGHTuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by rootEPSS 0.3%CVE-2026-62456HIGHVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2026-33706HIGHChamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher)EPSS 0.3%