Weaknesses of type CWE-269

2,507 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-16259CRITICALUix UserCenter <= 1.0.3 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2023-41076HIGHAn app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.EPSS 0.3%CVE-2025-61429HIGHAn issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request.EPSS 0.3%CVE-2026-21223HIGHMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2025-67781CRITICALAn issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulateEPSS 0.3%CVE-2025-24838HIGHImproper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow aEPSS 0.3%CVE-2022-24750HIGHLow privilege user is able to exploit the service and gain SYSTEM privileges in UltraVNC serverEPSS 0.3%CVE-2025-66314HIGHImproper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACEPSS 0.3%CVE-2026-18702MEDIUMImproper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic SettingsEPSS 0.3%CVE-2026-11616HIGHEvents Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2021-1447MEDIUMCisco Content Security Management Appliance Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-13292HIGHImproper access control in Google Cloud Apigee-X allows cross-tenant Analytics modification and log data access.EPSS 0.3%CVE-2025-2858HIGHPrivilege escalation vulnerability in saTECH BCUEPSS 0.3%CVE-2026-97895MEDIUMkrayin laravel-crm User Management UserController.php privileges managementEPSS 0.3%CVE-2020-35593—BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.EPSS 0.3%CVE-2024-6359MEDIUMPrivilege escalation vulnerabilityEPSS 0.3%CVE-2026-46696LOWOctober CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder CallsEPSS 0.3%CVE-2026-21963MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.3%CVE-2025-13534MEDIUMELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX ActionEPSS 0.3%CVE-2025-7044HIGHPrivilege Escalation in MAAS via Websocket Request ManipulationEPSS 0.3%