Falhas do tipo CWE-269

2.510 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-73747LOWLocal Privilege Escalation Vulnerability in HPE Networking Fabric ComposerEPSS 0.1%CVE-2026-28548HIGHVulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service coEPSS 0.1%CVE-2026-7994HIGHInappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level pEPSS 0.1%CVE-2023-21397—In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of priEPSS 0.1%CVE-2024-31334MEDIUMIn DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This coEPSS 0.1%CVE-2026-11308MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malEPSS 0.1%CVE-2024-40662HIGHIn scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local esEPSS 0.1%CVE-2025-13917HIGHElevation of Privileges in Web Security Services (WSS) AgentEPSS 0.1%CVE-2021-25515MEDIUMAn improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.EPSS 0.1%CVE-2024-31311MEDIUMIn increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to loEPSS 0.1%CVE-2026-96812HIGHHost Root Sandbox Escape in gVisor via Character Device Passthrough and CUSEEPSS 0.1%CVE-2026-11229MEDIUMInappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation EPSS 0.1%CVE-2022-22263MEDIUMUnprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.EPSS 0.1%CVE-2026-0032HIGHIn multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local eEPSS 0.1%CVE-2026-79153HIGHSeclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that alEPSS 0.1%CVE-2023-20995—In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This couEPSS 0.1%CVE-2025-12683MEDIUMNULL DACL assigned to Named Pipe communicating with SYSTEM ServiceEPSS 0.1%CVE-2025-32345HIGHIn updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary userEPSS 0.1%CVE-2024-32906HIGHIn AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no adEPSS 0.1%CVE-2022-36861MEDIUMCustom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystEPSS 0.1%