Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2025-13851CRITICALBuyent Theme (with Buyent Classified Plugin) <= 1.0.7 - Unauthenticated Privilege Escalation via User RegistrationEPSS 0.3%CVE-2025-15100HIGHJAY Login & Register <= 2.6.03 - Authenticated (Subscriber+) Privilege Escalation via jay_panel_ajax_update_profileEPSS 0.3%CVE-2026-68821HIGHWindows Package Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-85128HIGHChoose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role RequestEPSS 0.3%CVE-2025-3438MEDIUMMStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege EscalationEPSS 0.3%CVE-2026-11423CRITICALPath Traversal in Altium Enterprise Server Collaboration Service Allows Privilege EscalationEPSS 0.3%CVE-2024-27301HIGHPrivilege Escalation Abusing installer in SupportAppEPSS 0.3%CVE-2025-50069HIGHVulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. EasiEPSS 0.3%CVE-2026-20308MEDIUMCisco IOS XE Software Web-Based Management Interface VulnerabilityEPSS 0.3%CVE-2024-47853HIGHAn issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into MahEPSS 0.3%CVE-2025-6080HIGHWPGYM <= 67.7.0 - Missing Authorization to Admin Account CreationEPSS 0.3%CVE-2023-50677HIGHAn issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cEPSS 0.3%CVE-2026-60342MEDIUMVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2025-67793CRITICALAn issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permEPSS 0.3%CVE-2025-12424CRITICALPrivilege Escalation through SUID-bit BinaryEPSS 0.3%CVE-2023-52107HIGHVulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect serviceEPSS 0.3%CVE-2018-17954CRITICALcrowbar provision leaks admin password to all nodes in cleartextEPSS 0.3%CVE-2023-46756—Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up wEPSS 0.3%CVE-2024-6240HIGHImproper privilege management vulnerability in Parallels DesktopEPSS 0.3%