Falhas do tipo CWE-269

2.488 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2025-2232CRITICALRealteo - Real Estate Plugin by Purethemes <= 1.2.8 - Authentication Bypass via 'do_register_user'EPSS 0.5%CVE-2026-9018HIGHEasy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' ParameterEPSS 0.5%CVE-2026-55843HIGHSnipe-IT: Improper Privilege ManagementEPSS 0.5%CVE-2025-52915HIGHK7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminEPSS 0.5%CVE-2022-46172MEDIUMauthentik allows existing authenticated users to create arbitrary accountsEPSS 0.5%CVE-2024-33374CRITICALIncorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal withEPSS 0.5%CVE-2026-51119CRITICALAn issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser componentsEPSS 0.5%CVE-2024-30542CRITICALWordPress WholesaleX plugin <= 1.3.2 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2023-51476CRITICALWordPress WP MLM Unilevel plugin <= 4.0 - Unauthenticated Account Takeover vulnerabilityEPSS 0.5%CVE-2023-51481CRITICALWordPress Local Delivery Drivers for WooCommerce plugin <= 1.9.0 - Unauthenticated Account Takeover vulnerabilityEPSS 0.5%CVE-2022-32907HIGHThis issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary coEPSS 0.5%CVE-2024-12398HIGHAn improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) anEPSS 0.5%CVE-2026-40172HIGHauthentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuserEPSS 0.5%CVE-2026-76687HIGHAuthenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2024-38770CRITICALWordPress Backup and Staging by WP Time Capsule plugin <= 1.22.20 - Authentication Bypass and Privilege Escalation VulnerabilityEPSS 0.5%CVE-2020-13513HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2020-13514HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2020-13515HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/EPSS 0.5%CVE-2020-13512HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2022-41339HIGHIn Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.EPSS 0.5%