Falhas do tipo CWE-269

2.509 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2023-30988HIGHIBM i privilege escalationEPSS 0.2%CVE-2023-30989HIGHIBM i privilege escalationEPSS 0.2%CVE-2026-15380MEDIUMLocal privilege escalation in Symantec ITMSEPSS 0.2%CVE-2026-2914HIGHCyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elEPSS 0.2%CVE-2026-73974MEDIUMlinuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)EPSS 0.2%CVE-2022-41700MEDIUMInsecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticatEPSS 0.2%CVE-2026-76259HIGHImproper Privilege Management on the Management Port in Splunk Enterprise for WindowsEPSS 0.2%CVE-2023-41784MEDIUMPermissions and Access Control Vulnerability in ZTE Red Magic 8 ProEPSS 0.2%CVE-2025-64507HIGHIncus vulnerable to local privilege escalation through custom storage volumesEPSS 0.2%CVE-2026-16874HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2017-6894HIGHA vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that aEPSS 0.2%CVE-2025-13918MEDIUMElevation of Privileges in Symantec Endpoint Protection Windows ClientEPSS 0.2%CVE-2026-28919HIGHA consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS TahoEPSS 0.2%CVE-2022-25631HIGHSymantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a tEPSS 0.2%CVE-2026-29111MEDIUMsystemd: Local unprivileged user can trigger an assertEPSS 0.2%CVE-2022-46334HIGHProofpoint Enterprise Protection Local Privilege EscalationEPSS 0.2%CVE-2026-39118HIGHAn issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke EPSS 0.2%CVE-2026-53565HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2026-8069HIGHPredatorSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2023-25011HIGHPC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the registry as administrEPSS 0.2%