Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2025-11168HIGHMementor Core <= 2.2.5 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2026-16071MEDIUMKeycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundaryEPSS 0.3%CVE-2026-73714HIGHAuthenticated Sensitive Information Disclosure in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2020-7544—A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause prEPSS 0.3%CVE-2026-45801MEDIUMGLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)EPSS 0.3%CVE-2024-22795HIGHInsecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the RechecEPSS 0.3%CVE-2025-25202MEDIUMAsh Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`EPSS 0.3%CVE-2026-83241HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2026-5193MEDIUMEssential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_userEPSS 0.3%CVE-2025-6366HIGHEvent List <= 2.0.4 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2023-46810HIGHA local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute cEPSS 0.3%CVE-2025-45737MEDIUMAn issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafteEPSS 0.3%CVE-2013-10052HIGHZPanel zsudo Local Privilege EscalationEPSS 0.3%CVE-2026-14805HIGHConsulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAXEPSS 0.3%CVE-2025-54996HIGHOpenBao Root Namespace Operator May Elevate Token PrivilegesEPSS 0.3%CVE-2024-2003HIGHLocal Privilege Escalation in Quarantine of ESET products for WindowsEPSS 0.3%CVE-2025-59697HIGHEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.3%CVE-2026-48210MEDIUMPossible information disclosure via External InterfaceEPSS 0.3%CVE-2026-73755MEDIUMPrivilege Escalation via Unauthorized Access to Sensitive Session InformationEPSS 0.3%CVE-2023-0664HIGHA flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's WinEPSS 0.3%