Weaknesses of type CWE-269

2,488 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2022-39395CRITICALVela Insecure DefaultsEPSS 1.2%CVE-2023-42468—The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls without user consentEPSS 1.2%CVE-2022-2273—Simple Membership < 4.1.3 - Membership Privilege EscalationEPSS 1.2%CVE-2024-38089CRITICALMicrosoft Defender for IoT Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2021-24289—Store Locator Plus <= 5.5.14 - Authenticated Privilege EscalationEPSS 1.1%CVE-2022-1397HIGHAPI Privilege Escalation in alextselegidis/easyappointmentsEPSS 1.1%CVE-2022-24783CRITICALSandbox bypass leading to arbitrary code execution in DenoEPSS 1.1%CVE-2022-39286HIGHExecution with Unnecessary Privileges in JupyterAppEPSS 1.1%CVE-2021-43835HIGHPrivilege escalation in the Sulu Admin panelEPSS 1.1%CVE-2022-41032HIGHNuGet Client Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2022-23604HIGHPrivilege escalation in DefenderEPSS 1.1%CVE-2024-13997CRITICALNagios XI < 2024R1.1.3 Privilege Escalation via Migrate Server Feature to Root on HostEPSS 1.1%CVE-2024-14009CRITICALNagios XI < 2024R1.0.1 Privilege Escalation via System ProfileEPSS 1.1%CVE-2022-30526HIGHA privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEEPSS 1.1%CVE-2019-11270HIGHUAA clients.write vulnerabilityEPSS 1.1%CVE-2023-27654CRITICALAn issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.EPSS 1.1%CVE-2025-7341CRITICALHT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File DeletionEPSS 1.1%CVE-2023-5408HIGHOpenshift: modification of node role labelsEPSS 1.1%CVE-2025-14533CRITICALAdvanced Custom Fields: Extended <= 0.9.2.1 - Unauthenticated Privilege Escalation via Insert User Form ActionEPSS 1.1%CVE-2024-26247MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 1.1%