Falhas do tipo CWE-269

2.495 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2024-23253HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a useEPSS 0.4%CVE-2026-44231CRITICALRT: Privilege escalation and information disclosure via REST 2.0 user collection endpointEPSS 0.4%CVE-2024-47000HIGHService Users Deactivation not Working in ZitadelEPSS 0.4%CVE-2024-5909MEDIUMCortex XDR Agent: Local Windows User Can Disable the AgentEPSS 0.4%CVE-2025-59790MEDIUMApache Kvrocks: RESET command grants admin privilegesEPSS 0.4%CVE-2026-5141HIGHImproper Access Control in TUBITAK BILGEM's Pardus Software CenterEPSS 0.4%CVE-2024-36046CRITICALInfoblox NIOS through 8.6.4 executes with more privileges than required.EPSS 0.4%CVE-2025-6994CRITICALReveal Listing <= 3.3 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2023-44106—API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perforEPSS 0.4%CVE-2023-44105—Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cEPSS 0.4%CVE-2025-23208HIGHIdP group membership revocation ignored in zotEPSS 0.4%CVE-2026-9999HIGHInappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inEPSS 0.4%CVE-2022-23743—Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weaEPSS 0.4%CVE-2012-10022HIGHKloxo <= 6.1.12 Local Privilege EscalationEPSS 0.4%CVE-2018-14828—Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files EPSS 0.4%CVE-2026-16764MEDIUMOWASP DefectDojo API/Web serializers.py UserSerializer privileges managementEPSS 0.4%CVE-2026-60941HIGHVulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versiEPSS 0.4%CVE-2026-8980CRITICALPrivilege EscalationEPSS 0.4%CVE-2026-12687HIGHProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group IDEPSS 0.4%CVE-2026-13610HIGHKiviCare < 4.5.2 - Unauthenticated Privilege Escalation via RegistrationEPSS 0.4%