Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2025-32974CRITICALorg.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't consider TextAreas with default content typeEPSS 0.4%CVE-2024-5525HIGHImproper privilege management vulnerability in AstrotalksEPSS 0.4%CVE-2026-26010HIGHLeaky JWTs in OpenMetadata exposing highly-privileged bot usersEPSS 0.4%CVE-2024-46999HIGHUser Grant Deactivation not Working in ZitadelEPSS 0.4%CVE-2026-23990MEDIUMFlux Operator Web UI Impersonation Bypass via Empty OIDC ClaimsEPSS 0.4%CVE-2026-88817HIGHPrivilege escalation via legacy access group creation endpointEPSS 0.4%CVE-2021-21428CRITICALCreation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generatorEPSS 0.4%CVE-2026-45043CRITICALRustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including RootEPSS 0.4%CVE-2022-3419MEDIUMAutomatic User Roles Switcher < 1.1.2 - Subscriber+ Privilege EscalationEPSS 0.4%CVE-2023-52105HIGHThe nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.EPSS 0.4%CVE-2023-52716HIGHVulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vEPSS 0.4%CVE-2023-52116HIGHPermission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service EPSS 0.4%CVE-2025-13540CRITICALTiare Membership <= 1.2 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2025-13559CRITICALEduKart Pro <= 1.0.3 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2024-3388MEDIUMPAN-OS: User Impersonation in GlobalProtect SSL VPNEPSS 0.3%CVE-2025-28401MEDIUMAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameterEPSS 0.3%CVE-2024-30150MEDIUMAn unauthenticated privilege escalation vulnerability affects HCL MyCloudEPSS 0.3%CVE-2025-13764CRITICALWP CarDealer <= 1.2.16 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2025-13675CRITICALTiger <= 101.2.1 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2025-13538CRITICALFindAll Listing <= 1.0.5 - Unauthenticated Privilege EscalationEPSS 0.3%