Falhas do tipo CWE-269

2.489 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2025-28399CRITICALAn issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address ControlEPSS 0.6%CVE-2023-28855MEDIUMFields GLPI plugin vulnerable to unauthorized write access to additional fieldsEPSS 0.6%CVE-2023-29166A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate prEPSS 0.6%CVE-2024-29667CRITICALSQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate priEPSS 0.6%CVE-2021-34487HIGHWindows Event Tracing Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-0222HIGHA CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the contEPSS 0.6%CVE-2024-1908MEDIUMImproper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed Privilege EscalationEPSS 0.6%CVE-2023-36569HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-27518HIGHAn issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a cEPSS 0.6%CVE-2024-8100HIGHOn affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.EPSS 0.6%CVE-2024-44076CRITICALIn Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.EPSS 0.6%CVE-2024-9941HIGHWPGYM <= 67.1.0 - Missing Authorization to Authenticated (Subscriber+) Privilege EscalationEPSS 0.6%CVE-2022-41604HIGHCheck Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissiEPSS 0.6%CVE-2022-20739HIGHCisco SD-WAN vManage Software Privilege Escalation VulnerabilityEPSS 0.6%CVE-2026-52533CRITICALAn issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component fileEPSS 0.6%CVE-2022-26795HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-33398HIGHThere is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to imEPSS 0.6%CVE-2026-59245HIGHApache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)EPSS 0.6%CVE-2023-41957HIGHWordPress Simple Membership plugin <= 4.3.4 - Unauthenticated Membership Role Privilege Escalation vulnerabilityEPSS 0.6%CVE-2022-33640HIGHSystem Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege VulnerabilityEPSS 0.6%