Falhas do tipo CWE-269

2.488 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2023-36765HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2016-15002HIGHMONyog Ultimate Cookie privileges managementEPSS 1.0%CVE-2022-27487HIGHA improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptorEPSS 1.0%CVE-2021-34766MEDIUMCisco Smart Software Manager Privilege Escalation VulnerabilityEPSS 1.0%CVE-2025-49758HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2026-85979HIGHCommand Injection in Puppet EnterpriseEPSS 1.0%CVE-2026-25770CRITICALWazuh has Privilege Escalation to Root via Cluster Protocol File WriteEPSS 1.0%CVE-2021-36207HIGHMetasys privilege managementEPSS 1.0%CVE-2022-31707HIGHvRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the ImpoEPSS 1.0%CVE-2026-72830HIGHGrav API Plugin before 1.0.13 RCE via ConfigController scope bypassEPSS 0.9%CVE-2022-32801HIGHThis issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to gain root privileges.EPSS 0.9%CVE-2021-36302CRITICALAll Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user EPSS 0.9%CVE-2021-25442Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.EPSS 0.9%CVE-2023-6099HIGHShenzhen Youkate Industrial Facial Love Cloud Payment System Account SystemMng.ashx privileges managementEPSS 0.9%CVE-2020-12495CRITICALENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege managementEPSS 0.9%CVE-2024-45173HIGHAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MEPSS 0.9%CVE-2024-24892HIGHUnauthorized RCE in migration-toolsEPSS 0.9%CVE-2023-4404CRITICALDonation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege EscalationEPSS 0.9%CVE-2018-25040MEDIUMuTorrent Web HTTP RPC Server privileges managementEPSS 0.9%CVE-2022-29164HIGHPrivilege Escalation in argo-workflowsEPSS 0.9%