Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-19005MEDIUMnanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges managementEPSS 0.4%CVE-2024-11218HIGHPodman: buildah: container breakout by using --jobs=2 and a race condition when building a malicious containerfileEPSS 0.4%CVE-2025-53105HIGHGLPI permits unauthorized rules execution orderEPSS 0.4%CVE-2026-73788MEDIUMPrivilege Escalation in ClearPass OnGuard AgentEPSS 0.4%CVE-2024-2297HIGHBricksbuilder <= 1.9.6.1 - Authenticated (Contributor+) Privilege Escalation via create_autosaveEPSS 0.4%CVE-2026-31836HIGHMass Assignment Privilege Escalation in CheckmateEPSS 0.4%CVE-2026-66782MEDIUMSubmariner-operator: operator clusterrole grants cluster-wide create/update on all configmapsEPSS 0.4%CVE-2026-47413CRITICALpraisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/membersEPSS 0.4%CVE-2026-15142HIGHReal Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID CollisionEPSS 0.4%CVE-2026-47416CRITICALpraisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}EPSS 0.4%CVE-2024-1764HIGHImproper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continueEPSS 0.4%CVE-2026-46899CRITICALVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions thEPSS 0.4%CVE-2026-32106MEDIUMStudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin AccountsEPSS 0.4%CVE-2024-21034MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.4%CVE-2024-22893HIGHOpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers EPSS 0.4%CVE-2026-86552MEDIUMA vulnerability that skips email ownership verification for account registration in ZTE SmartLife APPEPSS 0.4%CVE-2025-24805HIGHLocal Privilege Escalation in MobSFEPSS 0.4%CVE-2025-4335HIGHWoocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2026-60854HIGHVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectEPSS 0.4%CVE-2024-46549HIGHAn issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonatingEPSS 0.4%