Falhas do tipo CWE-269

2.490 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-16904HIGHIBM i is Affected By improper privilege management in Navigator for iEPSS 0.5%CVE-2021-38638HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-61463HIGHShiori Authenticated Privilege Escalation via PATCH /api/v1/auth/accountEPSS 0.5%CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.5%CVE-2021-35309An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.EPSS 0.5%CVE-2024-9518CRITICALUserPlus <= 2.0 - Unauthenticated Privilege EscalationEPSS 0.5%CVE-2023-4607HIGHAn authenticated XCC user can change permissions for any user through a crafted API command.EPSS 0.5%CVE-2024-25343CRITICALTenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.EPSS 0.5%CVE-2025-0180CRITICALWP Foodbakery <= 4.7 - Unauthenticated Privilege Escalation in foodbakery_registration_validationEPSS 0.5%CVE-2024-34146MEDIUMJenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, aEPSS 0.5%CVE-2023-41808HIGHArbitrary File Read As Root Via GoTTY PageEPSS 0.5%CVE-2023-33327HIGHWordPress Leyka plugin <= 3.30.2 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-43403HIGHKanister has a potential risk which can be leveraged to make a cluster-level privilege escalationEPSS 0.5%CVE-2023-50921CRITICALAn issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privEPSS 0.5%CVE-2023-36496HIGHDelegated Admin Virtual Attribute Provider Privilege EscalationEPSS 0.5%CVE-2020-13518MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c402084 functionality of NZXT CAM 4.8.0. A specially craftedEPSS 0.5%CVE-2020-13511MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specialEPSS 0.5%CVE-2020-13516MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406144 functionality of NZXT CAM 4.8.0. A specially craftedEPSS 0.5%CVE-2025-46116HIGHAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.EPSS 0.5%CVE-2024-33569HIGHWordPress Instant Images plugin <= 6.1.0 - Arbitrary Option Update to Privilege Escalation vulnerabilityEPSS 0.5%