Falhas do tipo CWE-269

2.497 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-83191HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.4%CVE-2026-32212MEDIUMUniversal Plug and Play (upnp.dll) Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-83351HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploEPSS 0.4%CVE-2026-80467HIGHAdvanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privilege Escalation via Front-End User Insert ActionEPSS 0.4%CVE-2026-83254HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-83192HIGHVulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-2EPSS 0.4%CVE-2026-83169HIGHVulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). Supported versions tEPSS 0.4%CVE-2023-41743HIGHLocal privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber ProtectEPSS 0.4%CVE-2026-94381HIGHMISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via updateLoginTimeEPSS 0.4%CVE-2026-9327MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.4%CVE-2020-11640HIGHElevation of PrivilegeEPSS 0.4%CVE-2026-53645HIGHFOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalationEPSS 0.4%CVE-2026-88891HIGHOpenPanel Read-Only Access Level Enforcement Bypass via MutationsEPSS 0.4%CVE-2026-43978HIGHwger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managersEPSS 0.4%CVE-2026-24894HIGHFrankenPHP leaks session data between requests in worker modeEPSS 0.4%CVE-2021-23877MEDIUMMcAfee Total Protection (MTP) - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2024-42798HIGHAn Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara MusiEPSS 0.4%CVE-2025-8899HIGHPaid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.3.20 - Authenticated (Author+) Privilege EscalationEPSS 0.4%CVE-2025-3101HIGHConfigurator Theme Core <= 1.4.7 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2025-28237HIGHAn issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON EPSS 0.4%