Falhas do tipo CWE-269

2.509 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2024-21813HIGHExposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2025-24307LOWImproper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow aEPSS 0.2%CVE-2026-7977MEDIUMInappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a EPSS 0.2%CVE-2022-23455HIGHPotential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromEPSS 0.2%CVE-2025-27847MEDIUMIn ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.EPSS 0.2%CVE-2022-32931MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to EPSS 0.2%CVE-2025-27846MEDIUMIn ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOEPSS 0.2%CVE-2022-3369HIGHImproper handling of registry symbolic links in Bitdefender EnginesEPSS 0.2%CVE-2023-7241HIGHWebroot Antivirus COM-Hijacking LPEEPSS 0.2%CVE-2022-41975HIGHRealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.EPSS 0.2%CVE-2021-42082HIGHLocal Privilege Escalation to root in OSNEXUS QuantaStor before 6.0.0.355EPSS 0.2%CVE-2023-0221MEDIUMProduct security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypEPSS 0.2%CVE-2024-22106HIGHImproper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cauEPSS 0.2%CVE-2024-25088HIGHImproper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.EPSS 0.2%CVE-2024-21807CRITICALImproper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may EPSS 0.2%CVE-2026-12450MEDIUMInappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive infEPSS 0.2%CVE-2024-27357MEDIUMAn issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, andEPSS 0.2%CVE-2023-42952MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOEPSS 0.2%CVE-2025-36633HIGHLocal Privilege EscalationEPSS 0.2%CVE-2026-40001MEDIUMLocal privilege escalation vulnerability in ZTE PROCESS Guard service of the cloud computer clientEPSS 0.2%