Falhas do tipo CWE-269

2.495 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-18467CRITICALPaytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' ParameterEPSS 0.4%CVE-2026-62145HIGHLocal Privilege Escalation in Gaia PortalEPSS 0.4%CVE-2018-14787—In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalEPSS 0.4%CVE-2026-18249HIGHIBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java RuntimeEPSS 0.4%CVE-2022-30739MEDIUMImproper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number withEPSS 0.4%CVE-2026-78999HIGHImproper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderEPSS 0.4%CVE-2026-81818HIGHFlowintel Organization Administrator Can Reset Full Administrator Password and Escalate PrivilegesEPSS 0.4%CVE-2017-20112HIGHIVPN Client privileges managementEPSS 0.4%CVE-2017-12728—An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-admiEPSS 0.4%CVE-2026-46901CRITICALVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions thEPSS 0.4%CVE-2026-44543HIGHLocal Path Provisioner: HelperPod Template InjectionEPSS 0.4%CVE-2024-2228HIGHIdentityIQ Authorization of QuickLink Target Identities VulnerabilityEPSS 0.4%CVE-2023-21513MEDIUMImproper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to opeEPSS 0.4%CVE-2024-41903HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts thEPSS 0.4%CVE-2026-62473HIGHVulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that arEPSS 0.4%CVE-2025-30475HIGHDell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker wiEPSS 0.4%CVE-2026-60719CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.4%CVE-2026-86195HIGHgrav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super FlagEPSS 0.4%CVE-2023-47837HIGHWordPress ARMember plugin <= 4.0.10 - Membership Plan Bypass vulnerabilityEPSS 0.4%CVE-2025-24353MEDIUMDirectus privilege escalation vulnerability using Share featureEPSS 0.4%