Weaknesses of type CWE-269

2,513 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2026-44987LOWSysReptor: Privilege Escalation from User Admin to SuperuserEPSS 0.3%CVE-2020-6968—Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges through the modification of local configuratiEPSS 0.3%CVE-2019-18899MEDIUMapt-cacher-ng insecure use of /run/apt-cacher-ngEPSS 0.3%CVE-2022-42849HIGHAn access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 anEPSS 0.3%CVE-2025-50062HIGHVulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). SuppoEPSS 0.3%CVE-2021-22732—Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code executEPSS 0.3%CVE-2026-62453MEDIUMVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2025-8309HIGHUser privilege escalation vulnerabilityEPSS 0.3%CVE-2026-62524MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affEPSS 0.3%CVE-2026-92053HIGHPrivilege escalation in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-62525MEDIUMVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that EPSS 0.3%CVE-2026-61304MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.3%CVE-2024-22069HIGHPermission and Access Control Vulnerability in ZXV10 XT802/ET301EPSS 0.3%CVE-2026-62474MEDIUMVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versionEPSS 0.3%CVE-2026-61216MEDIUMVulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2025-2324MEDIUMA MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folderEPSS 0.3%CVE-2025-64436MEDIUMKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between NodesEPSS 0.3%CVE-2025-22621MEDIUMPrivilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAREPSS 0.3%CVE-2024-6908MEDIUMAdmin Can Escalate Privileges to SuperAdmin Using Manual PUT RequestEPSS 0.3%CVE-2022-1256HIGHImproper Privilege Management in McAfee Agent for WindowsEPSS 0.3%