Falhas do tipo CWE-269

2.510 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-49501MEDIUMDell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vuEPSS 0.2%CVE-2023-51429MEDIUM Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. EPSS 0.2%CVE-2025-54821LOWAn Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11EPSS 0.2%CVE-2026-26946MEDIUMDell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerabEPSS 0.2%CVE-2026-26947MEDIUMDell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulneraEPSS 0.2%CVE-2026-12502HIGHLoytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudoEPSS 0.2%CVE-2025-6943LOWSecret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to rEPSS 0.2%CVE-2023-40375HIGHIBM i privilege escalationEPSS 0.2%CVE-2026-84083HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.2%CVE-2025-49156HIGHA link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected insEPSS 0.2%CVE-2026-29121HIGH`/sbin/ip` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPEEPSS 0.1%CVE-2023-40685HIGHIBM i privilege escalationEPSS 0.1%CVE-2026-75777HIGHMultiple vulnerabilities in IBM Aspera Enterprise WebappsEPSS 0.1%CVE-2021-23893HIGHPrivilege Escalation vulnerability in McAfee Drive Encryption (MDE)EPSS 0.1%CVE-2026-28889MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary fileEPSS 0.1%CVE-2026-23599HIGHLocal Privilege Escalation Vulnerability in HPE Aruba Networking Clear Pass Policy Manager OnGuard for LinuxEPSS 0.1%CVE-2026-30769HIGHAn issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sEPSS 0.1%CVE-2022-37929MEDIUMImproper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary FlEPSS 0.1%CVE-2026-19220LOWForminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege EscalationEPSS 0.1%CVE-2026-6389HIGHIBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerabilityEPSS 0.1%