Falhas do tipo CWE-269

2.464 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-58053CRITICALGitea act_runner - Container Hardening Bypass via Workflow Container OptionsEPSS 0.4%CVE-2026-56216HIGHCapgo - Scope Escalation via API Key Creation in /functions/v1/apikeyEPSS 0.4%CVE-2025-0177CRITICALJavo Core <= 3.0.0.080 - Unauthenticated Privilege Escalation in ajax_signupEPSS 0.4%CVE-2021-4314MEDIUMIt is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. ThiEPSS 0.4%CVE-2026-13741HIGHDigits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' ParameterEPSS 0.4%CVE-2026-65603HIGHGrav Login Plugin 3.8.11 Privilege Escalation via Profile UpdateEPSS 0.4%CVE-2026-2563MEDIUMJingDong JD Cloud Box AX6600 jdcapp_rpc controlDevice get_status privileges managementEPSS 0.4%CVE-2026-17553HIGHShopping Cart & eCommerce Store <= 5.9.3 - Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX ActionEPSS 0.4%CVE-2024-8810HIGHPrivilege Management vulnerability was identified in GitHub Enterprise Server that allowed GitHub Apps to grant themselves write accessEPSS 0.4%CVE-2025-36729HIGHRACOM M!DGE2 Privilege Escalation via SDK Testing EndpointEPSS 0.4%CVE-2026-39386HIGHNeko has Self-service Privilege Escalation for Authenticated UsersEPSS 0.4%CVE-2026-45395HIGHOpen WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code ExecutionEPSS 0.4%CVE-2025-21199MEDIUMAzure Agent Installer for Backup and Site Recovery Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-33226CRITICALAn issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and eEPSS 0.4%CVE-2024-51392HIGHAn issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php componentEPSS 0.4%CVE-2025-5931HIGHDokan Pro <= 4.0.5 - Authenticated (Vendor+) Privilege EscalationEPSS 0.4%CVE-2026-61176MEDIUMVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.4%CVE-2026-26725CRITICALAn issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AEPSS 0.4%CVE-2019-13690CRITICALInappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilegEPSS 0.4%CVE-2020-7335HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.4%