Falhas do tipo CWE-269

2.489 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-73664HIGHFreePBX: Authenticated Arbitrary SSH Key Injection via Backup ModuleEPSS 0.7%CVE-2024-33308CRITICALAn issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the EmeEPSS 0.7%CVE-2025-2798CRITICALWoffice <= 5.4.21 - Authentication Bypass via Registration RoleEPSS 0.7%CVE-2022-43749MEDIUMImproper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authEPSS 0.6%CVE-2026-66015HIGHJFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.EPSS 0.6%CVE-2024-27181HIGHApache Linkis Basic management services: Privilege Escalation Attack vulnerabilityEPSS 0.6%CVE-2023-51546HIGHWordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerabilityEPSS 0.6%CVE-2024-8853CRITICALWebo-facto <= 1.40 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2023-28339HIGHOpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTEEPSS 0.6%CVE-2023-0524HIGHAs part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a maliciouEPSS 0.6%CVE-2023-27094HIGHAn issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the tenant Management moEPSS 0.6%CVE-2024-0439HIGHUser can manually send request at manager permission to modify system configurationsEPSS 0.6%CVE-2023-46647HIGHImproper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation EPSS 0.6%CVE-2023-47682HIGHWordPress WP User Frontend plugin <= 3.6.5 - Authenticated Privilege Escalation vulnerabilityEPSS 0.6%CVE-2022-31672MEDIUMVMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate EPSS 0.6%CVE-2025-29165CRITICALAn issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample componentEPSS 0.6%CVE-2024-0751HIGHA malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, aEPSS 0.6%CVE-2023-37058CRITICALInsecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges vEPSS 0.6%CVE-2023-21848HIGHVulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Admin Configuration). TheEPSS 0.6%CVE-2022-34703HIGHWindows Partition Management Driver Elevation of Privilege VulnerabilityEPSS 0.6%