Falhas do tipo CWE-269

2.490 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2020-13512HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2023-43845CRITICALAten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials EPSS 0.5%CVE-2024-25847CRITICALSQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6EPSS 0.5%CVE-2023-50726MEDIUMUsers with `create` but not `override` privileges can perform local sync in argo-cdEPSS 0.5%CVE-2020-13517MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0. A specially craftedEPSS 0.5%CVE-2022-4264MEDIUMIncorrect privilege assignment in M-Files Web ServerEPSS 0.5%CVE-2024-4545HIGHEDB Postgres Advanced Server (EPAS) authenticated file read permissions bypass using edbldrEPSS 0.5%CVE-2025-4315HIGHCubeWP – All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.5%CVE-2026-33509HIGHpyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script ConfigurationEPSS 0.5%CVE-2022-4270LOWIncorrect privilege assignment in M-Files Web ServerEPSS 0.5%CVE-2024-44893CRITICALAn issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET requeEPSS 0.5%CVE-2020-35517A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest usEPSS 0.5%CVE-2022-25311HIGHA vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All EPSS 0.5%CVE-2023-47782HIGHWordPress Thrive Theme Builder theme < 3.24.0 - Authenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-47409HIGHpraisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}EPSS 0.5%CVE-2026-47412HIGHpraisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}EPSS 0.5%CVE-2022-42855HIGHA logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOSEPSS 0.5%CVE-2024-7291HIGHJetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege EscalationEPSS 0.5%CVE-2023-48319MEDIUMWordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-16904HIGHIBM i is Affected By improper privilege management in Navigator for iEPSS 0.5%