Falhas do tipo CWE-269

2.509 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2025-33187CRITICALNVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areasEPSS 0.2%CVE-2023-41138HIGHThe AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user pEPSS 0.2%CVE-2026-87183HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2026-12313MEDIUMInformation disclosure, sandbox escape in the Security: Process Sandboxing componentEPSS 0.2%CVE-2026-49883CRITICALIn checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permissioEPSS 0.2%CVE-2026-46877MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affecEPSS 0.2%CVE-2024-23764MEDIUMCertain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server SecuriEPSS 0.2%CVE-2021-3439HIGHHP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate tEPSS 0.2%CVE-2023-35140MEDIUMThe improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated EPSS 0.2%CVE-2025-65621MEDIUMSnipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administratorEPSS 0.2%CVE-2023-40155MEDIUMUncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalEPSS 0.2%CVE-2023-5993HIGHPrivilege Escalation in SafeNet Authentication Client InstallerEPSS 0.2%CVE-2022-3990HIGHHPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customers who opted for autoEPSS 0.2%CVE-2024-9002HIGHCWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and avEPSS 0.2%CVE-2025-36631HIGHLocal Privilege EscalationEPSS 0.2%CVE-2025-37186HIGHLocal Privilege Escalation Vulnerability in HPE Aruba Networking Virtual Intranet Access (VIA) Client for LinuxEPSS 0.2%CVE-2024-4018HIGHPrivilege Escalation in U-Series ApplianceEPSS 0.2%CVE-2026-18759HIGHAn improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.EPSS 0.2%CVE-2024-52926MEDIUMDelinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.EPSS 0.2%CVE-2022-48227HIGHAn issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the instEPSS 0.2%