Falhas do tipo CWE-269

2.490 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-48010MEDIUMShopware: Privilege escalation: non-admin user with user:create ACL can create admin accountsEPSS 0.5%CVE-2023-47629HIGHPrivilege escalation through email sign-up in datahubEPSS 0.5%CVE-2024-0003CRITICALA condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the arrayEPSS 0.5%CVE-2026-8176HIGHLatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password ResetEPSS 0.5%CVE-2022-48283CRITICALA piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnEPSS 0.5%CVE-2022-48284CRITICALA piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnEPSS 0.5%CVE-2022-42046HIGHwfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalationEPSS 0.5%CVE-2026-49176HIGHWindows WalletService Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2024-39206HIGHAn issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup dueEPSS 0.5%CVE-2025-66428HIGHAn issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.EPSS 0.5%CVE-2024-33223HIGHAn issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute EPSS 0.5%CVE-2024-28905HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-68561HIGHWekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow ruleEPSS 0.5%CVE-2022-35764HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-1606LOWIncorrect privilege assignment in M-Files ServerEPSS 0.5%CVE-2022-35763HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-35765HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-60369CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60373HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-61094HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.5%