Falhas do tipo CWE-269

2.495 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-87165HIGHVulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award andEPSS 0.4%CVE-2026-83340HIGHVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affecteEPSS 0.4%CVE-2026-87162HIGHVulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). SuppoEPSS 0.4%CVE-2026-8157HIGHVitepos < 3.4.2 - Outlet Manager+ Privilege EscalationEPSS 0.4%CVE-2026-87759HIGHAdd User Autocomplete < 1.2 - Subscriber+ Privilege EscalationEPSS 0.4%CVE-2026-83189HIGHVulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that EPSS 0.4%CVE-2026-53527HIGHLeafWiki Vulnerable to Privilege Escalation via User Self-Service UpdateEPSS 0.4%CVE-2026-83148HIGHVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability alEPSS 0.4%CVE-2026-88904HIGHPuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege EscalationEPSS 0.4%CVE-2026-83121HIGHVulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12EPSS 0.4%CVE-2026-72534HIGHAuthentik Security authentik - Privilege EscalationEPSS 0.4%CVE-2026-83282CRITICALVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The suppoEPSS 0.4%CVE-2026-83194HIGHVulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are aEPSS 0.4%CVE-2026-83338HIGHVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported vEPSS 0.4%CVE-2026-83168HIGHVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported vEPSS 0.4%CVE-2026-83456HIGHVulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.4%CVE-2026-83120HIGHVulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectedEPSS 0.4%CVE-2026-47870HIGHVMware Avi Load Balancer Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-83348HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0EPSS 0.4%CVE-2026-83331HIGHVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.4%