Falhas do tipo CWE-269

2.489 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2022-35771HIGHWindows Defender Credential Guard Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2023-25701CRITICALWordPress WatchTowerHQ plugin <= 3.6.16 - Privilege EscalationEPSS 0.8%CVE-2025-11561HIGHSssd: sssd default kerberos configuration allows privilege escalation on ad-joined linux systemsEPSS 0.8%CVE-2026-12415CRITICALInvoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' ParameterEPSS 0.8%CVE-2021-27394A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (AllEPSS 0.8%CVE-2024-1442MEDIUMUser with permissions to create a data source can CRUD all data sourcesEPSS 0.8%CVE-2024-9636CRITICALPost Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege EscalationEPSS 0.8%CVE-2021-3919CRITICALA potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege aEPSS 0.8%CVE-2026-8809CRITICALAdvanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' ParameterEPSS 0.8%CVE-2026-22708HIGHCursor has a Terminal Tool Allowlist Bypass via Environment VariablesEPSS 0.8%CVE-2022-39032HIGHSmart eVision - Improper Privilege ManagementEPSS 0.8%CVE-2023-32696HIGHExcessive permissions for ckan userEPSS 0.8%CVE-2024-20374MEDIUMA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower ManagemeEPSS 0.8%CVE-2026-49819CRITICALUpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdEPSS 0.8%CVE-2024-22036CRITICALRancher Remote Code Execution via Cluster/Node DriversEPSS 0.8%CVE-2018-14825On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OEPSS 0.8%CVE-2024-22922CRITICALAn issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the lEPSS 0.8%CVE-2025-24254HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS VenturaEPSS 0.8%CVE-2023-32244CRITICALWordPress Woodmart Core plugin <= 1.0.36 - Privilege EscalationEPSS 0.8%CVE-2023-4140MEDIUMWP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege EscalationEPSS 0.8%