Falhas do tipo CWE-269

2.510 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2022-36861MEDIUMCustom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystEPSS 0.1%CVE-2023-21068—In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to localEPSS 0.1%CVE-2023-20680MEDIUMIn adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2023-21374—In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of pEPSS 0.1%CVE-2023-35667—In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a lEPSS 0.1%CVE-2026-58874HIGHIn multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead EPSS 0.1%CVE-2025-66324HIGHInput verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affeEPSS 0.1%CVE-2025-48613HIGHIn VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the EPSS 0.1%CVE-2026-0009HIGHIn multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege witEPSS 0.1%CVE-2023-21376MEDIUMIn Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosurEPSS 0.1%CVE-2023-20655HIGHIn mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code execution with no additEPSS 0.1%CVE-2023-40106HIGHIn sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. ThisEPSS 0.1%CVE-2025-6177HIGHChromeOS MiniOS Root Code Execution Bypass While Dev Mode BlockedEPSS 0.1%CVE-2024-22008HIGHIn config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatEPSS 0.1%CVE-2026-0023HIGHIn createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permisEPSS 0.1%CVE-2025-26462HIGHIn AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to EPSS 0.1%CVE-2025-26435HIGHIn updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary userEPSS 0.1%CVE-2026-24510MEDIUMDell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerability. A low privileged EPSS 0.1%CVE-2024-25987MEDIUMIn pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation EPSS 0.1%CVE-2026-28586LOWIn multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to loEPSS 0.1%