Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-15630CRITICALCVE-2026-15630EPSS 0.3%CVE-2023-53908HIGHHiSecOS 04.0.01 Privilege Escalation via User Role ModificationEPSS 0.3%CVE-2026-1010HIGHStored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege EscalationEPSS 0.3%CVE-2023-23427MEDIUM Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2022-24927MEDIUMImproper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files withoEPSS 0.3%CVE-2026-10522CRITICALSimple User Registration <= 6.9 - Unauthenticated Privilege Escalation to AdministratorEPSS 0.3%CVE-2023-7016HIGHPrivilege Escalation in SafeNet Authentication Client EPSS 0.3%CVE-2023-28640MEDIUMPermissions bypass in Apiman could enable authenticated attacker to unpermitted API KeyEPSS 0.3%CVE-2020-16122HIGHPackagekit's apt backend lets user install untrusted local packagesEPSS 0.3%CVE-2024-53706HIGHA vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges toEPSS 0.3%CVE-2022-48019HIGHThe components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to perform privilege escalEPSS 0.3%CVE-2026-73724HIGHAuthenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric ComposerEPSS 0.3%CVE-2025-14975HIGHCustom Login Page Customizer < 2.5.4 - Unauthenticated Arbitrary Password ResetEPSS 0.3%CVE-2023-50267MEDIUMMeterSphere horizontal privilege escalation vulnerability of resources in project scope.EPSS 0.3%CVE-2024-48729HIGHAn issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote authenticated attackeEPSS 0.3%CVE-2024-56335HIGHPrivilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwardenEPSS 0.3%CVE-2025-64489HIGHSuiteCRM: Privilege Escalation via Improper Session Invalidation and Inactive User BypassEPSS 0.3%CVE-2021-27765MEDIUMHCL BigFix Platform Server API is affected by Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-55550HIGHNextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product CatalogEPSS 0.3%CVE-2026-62515HIGHVulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). SupportedEPSS 0.3%