Weaknesses of type CWE-269

2,517 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2025-53914HIGHCalix GigaCenter ONT (Broadcom SoC) - Excessive PrivilegesEPSS 0.2%CVE-2025-39202HIGHA vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can seeEPSS 0.2%CVE-2023-32426—A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to gain root privileges.EPSS 0.2%CVE-2025-53027HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2022-36088MEDIUMGoCD Windows installations outside default location inadequately restrict installation file permissionsEPSS 0.2%CVE-2023-23497—A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey EPSS 0.2%CVE-2021-27483—ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilegEPSS 0.2%CVE-2026-61064MEDIUMVulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supported versions that EPSS 0.2%CVE-2026-88764MEDIUMSimple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_refEPSS 0.2%CVE-2025-52599MEDIUMInadequate account permissions managementEPSS 0.2%CVE-2026-62355MEDIUMTDengine: Standard User permission unexpectEPSS 0.2%CVE-2022-31594—A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.EPSS 0.2%CVE-2021-34745HIGHAppDynamics .NET Agent Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-54560MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A maliEPSS 0.2%CVE-2023-31005MEDIUMIBM Security Access Manager Container privilege escalationEPSS 0.2%CVE-2026-100578HIGHOpenClaw before 2026.7.1 Authorization Bypass via chat.sendEPSS 0.2%CVE-2020-36549HIGHGE Voluson S8 Windows Operating System Patches privileges managementEPSS 0.2%CVE-2025-6042HIGHLisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - Unauthenticated Privilege Escalation to EditorEPSS 0.2%CVE-2025-12726HIGHInappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the EPSS 0.2%CVE-2018-16497—In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job EPSS 0.2%