Falhas do tipo CWE-269

2.510 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2024-49558HIGHDell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerabilityEPSS 0.1%CVE-2024-20262MEDIUMA vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to EPSS 0.1%CVE-2026-15379MEDIUMArbitrary File Read as SYSTEM in Symantec ITMSEPSS 0.1%CVE-2024-5760HIGHThe Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shellEPSS 0.1%CVE-2023-40686MEDIUMIBM i privilege escalationEPSS 0.1%CVE-2026-82670MEDIUMIObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges managementEPSS 0.1%CVE-2025-10657HIGHDocker Desktop with ECI Fails to Enforce Socket Command RestrictionsEPSS 0.1%CVE-2026-58583HIGHFluxInk Color Management Driver local privilege escalationEPSS 0.1%CVE-2026-83211HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2026-83342HIGHVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). SupporteEPSS 0.1%CVE-2026-83147HIGHVulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported versionEPSS 0.1%CVE-2026-83118HIGHVulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected arEPSS 0.1%CVE-2024-31953MEDIUMAn issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used duEPSS 0.1%CVE-2026-30902HIGHZoom Clients for Windows - Improper Privilege ManagementEPSS 0.1%CVE-2026-83336HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported vEPSS 0.1%CVE-2026-83353HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.1%CVE-2026-0276LOWCortex XDR Broker VM: Privilege Escalation (PE) VulnerabilityEPSS 0.1%CVE-2026-83216HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2026-83214HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2021-3978HIGHImproper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpkiEPSS 0.1%