Weaknesses of type CWE-269

2,511 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2020-7330HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP) trialEPSS 0.3%CVE-2026-87164HIGHVulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that EPSS 0.3%CVE-2025-25872MEDIUMAn issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions functionEPSS 0.3%CVE-2026-73842CRITICALOpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutationEPSS 0.3%CVE-2026-16366HIGHPrivilege escalation in the DOM: Navigation componentEPSS 0.3%CVE-2022-32826HIGHAn authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, EPSS 0.3%CVE-2025-5494LOWPrivilege EscalationEPSS 0.3%CVE-2025-20346MEDIUMCisco Catalyst Center Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-56733HIGHZammad: Incorrect Authorization and Improper Privilege ManagementEPSS 0.3%CVE-2026-75924HIGHManaged-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants cluster-wide secret read/write and csr approvalEPSS 0.3%CVE-2025-31284MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to EPSS 0.3%CVE-2026-60371HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-31283MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administratorEPSS 0.3%CVE-2025-31285MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator EPSS 0.3%CVE-2025-31282MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administratEPSS 0.3%CVE-2023-7342HIGHBelden HiSecOS Web Server Privilege EscalationEPSS 0.3%CVE-2024-45752HIGHlogiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus seEPSS 0.3%CVE-2019-11288HIGHtcServer JMX Socket Listener Registry Rebinding Local Privilege EscalationEPSS 0.3%CVE-2025-68697HIGHSelf-hosted n8n has Legacy Code node that enables arbitrary file read/writeEPSS 0.3%CVE-2023-24483HIGHPrivilege Escalation to NT AUTHORITY\SYSTEM on the vulnerable VDAEPSS 0.3%