Falhas do tipo CWE-269

2.509 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2022-48227HIGHAn issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the instEPSS 0.2%CVE-2023-5671—HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software updates to mitigate EPSS 0.2%CVE-2025-62625MEDIUMImproper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentiaEPSS 0.2%CVE-2022-45853MEDIUMThe privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHIEPSS 0.2%CVE-2026-30892NONECrun incorrectly parses `crun exec` option `-u`, leading to privilege escalationEPSS 0.2%CVE-2023-5739HIGHCertain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.EPSS 0.2%CVE-2023-32487HIGH Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentiallyEPSS 0.2%CVE-2023-32490MEDIUM Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentiallyEPSS 0.2%CVE-2026-6423HIGHLocal privilege escalation via unauthenticated ALPC in ESET Inspect ConnectorEPSS 0.2%CVE-2024-21059HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. DifficulEPSS 0.2%CVE-2026-45176HIGHIdira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation ManipulationEPSS 0.2%CVE-2023-31432HIGHPrivilege issues in multiple commandsEPSS 0.2%CVE-2025-54595HIGHPearcleaner's unauthenticated access to privileged XPC helper allows root command executionEPSS 0.2%CVE-2023-21896HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. DEPSS 0.2%CVE-2023-51386HIGHSandbox Accounts for Events vulnerable to privilege escalation to read running events dataEPSS 0.2%CVE-2026-73974MEDIUMlinuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)EPSS 0.2%CVE-2026-15380MEDIUMLocal privilege escalation in Symantec ITMSEPSS 0.2%CVE-2022-37019MEDIUMHP PC BIOS May 2024 Security Updates for Potential Stack Buffer OverflowsEPSS 0.2%CVE-2023-30988HIGHIBM i privilege escalationEPSS 0.2%CVE-2023-45883—A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers EPSS 0.2%