Falhas do tipo CWE-269

2.510 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-83150HIGHVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability EPSS 0.1%CVE-2026-60833HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. DifficEPSS 0.1%CVE-2026-60661HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. DiEPSS 0.1%CVE-2026-61061HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affEPSS 0.1%CVE-2020-9080HIGHThere is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specifiEPSS 0.1%CVE-2024-5907MEDIUMCortex XDR Agent: Local Privilege Escalation (PE) VulnerabilityEPSS 0.1%CVE-2025-14252HIGHAn Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, andEPSS 0.1%CVE-2026-22536HIGHPRIVILEGE ESCALATION VIA SUDO COMMANDEPSS 0.1%CVE-2025-5687HIGHLocal privilege escalation vulnerability in Mozilla VPN clients for macOS v2.27.0 and below.EPSS 0.1%CVE-2025-36640HIGHLocal Privilege EscalationEPSS 0.1%CVE-2025-5028MEDIUMArbitrary file deletion vulnerability in ESET product installersEPSS 0.1%CVE-2026-35154MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.1%CVE-2024-0674MEDIUMPrivilege escalation vulnerability in Lamassu Bitcoin ATM Douro machinesEPSS 0.1%CVE-2026-17877HIGHInappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level priEPSS 0.1%CVE-2026-14124HIGHInappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OSEPSS 0.1%CVE-2026-17864HIGHInappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilegEPSS 0.1%CVE-2025-26513HIGHThe installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited cEPSS 0.1%CVE-2025-10650LOWImproper SSH Key Handling in Internal Debug Builds May Grant Cluster-Level Access to Non-Administrative UsersEPSS 0.1%CVE-2024-57062MEDIUMAn issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the sessEPSS 0.1%CVE-2023-21113HIGHIn multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege withEPSS 0.1%