Falhas do tipo CWE-269

2.509 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-61204CRITICALVulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supEPSS 0.2%CVE-2021-31839MEDIUMIncorrect permissions on McAfee Agent for Windows event folderEPSS 0.2%CVE-2022-48226HIGHAn issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During installation, an EXE gets executed out of C:\Windows\Temp. A standaEPSS 0.2%CVE-2025-43512HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14EPSS 0.2%CVE-2024-34332HIGHAn issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a crafted buffer sent tEPSS 0.2%CVE-2026-87273HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-9068HIGHRockwell Automation FactoryTalk® Linx Privilege Escalation VulnerabilitiesEPSS 0.2%CVE-2024-44147HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized accessEPSS 0.2%CVE-2025-9067HIGHRockwell Automation FactoryTalk® Linx Privilege Escalation VulnerabilitiesEPSS 0.2%CVE-2026-60406MEDIUMVulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The suppoEPSS 0.2%CVE-2026-35288HIGHVulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions EPSS 0.2%CVE-2026-61182MEDIUMVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The suEPSS 0.2%CVE-2026-40572CRITICALNovumOS has Arbitrary Memory Mapping via Syscall 15 (MemoryMapRange)EPSS 0.2%CVE-2026-87248MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2025-55581HIGHD-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. EPSS 0.2%CVE-2018-6674MEDIUMPrivilege escalation vulnerability in McAfee VSE when McTray run with elevated privilegesEPSS 0.2%CVE-2023-47145HIGHIBM Db2 for Windows privilege escalationEPSS 0.2%CVE-2024-33224HIGHAn issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privilegEPSS 0.2%CVE-2022-43535HIGHA vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. AEPSS 0.2%CVE-2023-25590HIGHLocal Privilege Escalation in ClearPass OnGuard Linux AgentEPSS 0.2%