Falhas do tipo CWE-269

2.510 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-12217HIGHDVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges managementEPSS 0.1%CVE-2025-15576HIGHJail chroot escape via fd exchange with a different jailEPSS 0.1%CVE-2024-20021MEDIUMIn atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of EPSS 0.1%CVE-2024-0024HIGHIn multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input vaEPSS 0.1%CVE-2021-25365MEDIUMAn improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.EPSS 0.1%CVE-2025-9912MEDIUMA local privilege escalation vulnerability in Nokia SR LinuxEPSS 0.1%CVE-2026-54099HIGHWindows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:mastersEPSS 0.1%CVE-2024-39342MEDIUMEntrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.eEPSS 0.1%CVE-2025-57840LOWPrivilege Bypass in ADBEPSS 0.1%CVE-2025-52347HIGHAn issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 BuEPSS 0.1%CVE-2025-69875HIGHA vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore pEPSS 0.1%CVE-2026-63349HIGHAnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groupsEPSS 0.1%CVE-2025-15561HIGHLocal Privilege Escalation in NesterSoft WorkTimeEPSS 0.1%CVE-2026-12518HIGHLocal privilege escalation in the Logi Options+ updater service on WindowsEPSS 0.1%CVE-2026-19915HIGHHP Support Assistant - Local Escalation of PrivilegeEPSS 0.1%CVE-2026-0029HIGHIn __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2024-31325HIGHIn multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to localEPSS 0.1%CVE-2024-36500HIGHPrivilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.1%CVE-2024-51521MEDIUMInput parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affectEPSS 0.1%CVE-2024-36499MEDIUMVulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect servicEPSS 0.1%