Falhas do tipo CWE-269

2.510 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-38765HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysEPSS 0.1%CVE-2026-83193HIGHVulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences). Supported versions that are affecEPSS 0.1%CVE-2026-29923HIGHThe pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL requeEPSS 0.1%CVE-2026-60162MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2026-86884MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, EPSS 0.1%CVE-2024-39574MEDIUMDell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local accessEPSS 0.1%CVE-2026-16743MEDIUMAccountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed usersEPSS 0.1%CVE-2026-83190HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2026-29122HIGH`/bin/date` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPEEPSS 0.1%CVE-2024-42050HIGHThe MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A locEPSS 0.1%CVE-2026-80166HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper PrivilegEPSS 0.1%CVE-2026-38766HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 functionEPSS 0.1%CVE-2025-67905HIGHMalwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target locationEPSS 0.1%CVE-2026-83597HIGHNetdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair ExecutionEPSS 0.1%CVE-2026-20044MEDIUMCisco Secure Firewall Management Center Command Injection VulnerabilityEPSS 0.1%CVE-2026-80178MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper PrivilegEPSS 0.1%CVE-2025-1121MEDIUMPrivilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physicEPSS 0.1%CVE-2023-47201MEDIUMA plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privilEPSS 0.1%CVE-2017-13165MEDIUMAn elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937.EPSS 0.1%CVE-2026-16703HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%