Falhas do tipo CWE-269

2.464 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2023-39734The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token anEPSS 0.6%CVE-2026-2631CRITICALDatalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2022-24072The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store weEPSS 0.6%CVE-2022-41268HIGHIn some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200EPSS 0.6%CVE-2026-13228HIGHLatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' ParameterEPSS 0.6%CVE-2023-39732The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broaEPSS 0.6%CVE-2023-39740The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadEPSS 0.6%CVE-2026-66818HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-12981CRITICALListee <= 1.1.6 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2020-13519HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/EPSS 0.6%CVE-2023-41243HIGHWordPress WPvivid Backup Plugin plugin <= 0.9.90 - Privilege Escalation on Staging Environment vulnerabilityEPSS 0.6%CVE-2024-33552CRITICALWordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerabilityEPSS 0.6%CVE-2022-3641HIGHElevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated useEPSS 0.6%CVE-2023-39733The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mEPSS 0.6%CVE-2024-2433MEDIUMPAN-OS: Improper Privilege Management Vulnerability in Panorama Software Leads to Availability LossEPSS 0.6%CVE-2023-46145HIGHWordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerabilityEPSS 0.6%CVE-2024-31498HIGHYubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windoEPSS 0.6%CVE-2025-57118CRITICALAn issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.phpEPSS 0.6%CVE-2024-7493CRITICALWPCOM Member <= 1.5.2.1 - Unauthenticated Privilege Escalation via User MetaEPSS 0.6%CVE-2026-16850HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.6%