Falhas do tipo CWE-269

2.489 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2023-7080HIGHArbitrary remote code execution within wrangler dev Workers sandboxEPSS 0.6%CVE-2023-48171HIGHAn issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.EPSS 0.6%CVE-2022-32840HIGHThis issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app mayEPSS 0.6%CVE-2023-33966HIGHDeno missing "--allow-net" permission check for built-in Node modulesEPSS 0.6%CVE-2026-76678HIGHAuthenticated Command Injection Vulnerability leads to Remote Code Execution in EdgeConnect SD-WAN GatewaysEPSS 0.6%CVE-2023-28261MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2017-20037MEDIUMSICUNET Access Controller privileges managementEPSS 0.6%CVE-2026-38529HIGHA Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attEPSS 0.6%CVE-2024-22752HIGHInsecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executableEPSS 0.6%CVE-2021-4200MEDIUMWrite access to the Catalog for any user when restricted-admin role is enabledEPSS 0.6%CVE-2026-75977HIGHMang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication CookieEPSS 0.6%CVE-2020-26063MEDIUMCisco Integrated Management Controller Software Authorization Bypass VulnerabilityEPSS 0.6%CVE-2024-9265CRITICALEcho RSS Feed Post Generator <= 5.4.6 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2025-11533CRITICALWP Freeio <= 1.2.21 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2020-36603MEDIUMThe HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calEPSS 0.6%CVE-2022-32829HIGHThis issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to eEPSS 0.6%CVE-2022-41948MEDIUMPrivilege Chaining with the user admin role in dhis2-coreEPSS 0.6%CVE-2021-34579HIGHPHOENIX CONTACT: FL MGUARD DM version 1.12.0 and 1.13.0 Improper Privilege ManagementEPSS 0.6%CVE-2025-29976HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2023-32197HIGHRancher's External RoleTemplates can lead to privilege escalationEPSS 0.6%