Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2025-46364CRITICALDell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape VulnerabilitEPSS 0.3%CVE-2023-23428LOW Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2024-5759MEDIUMImproper privilege managementEPSS 0.3%CVE-2023-23430LOW Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2026-8327MEDIUMConcrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.EPSS 0.3%CVE-2025-8660MEDIUMPrivilege Escalation in Symantec PGP Encryption 11.0.1EPSS 0.3%CVE-2023-25144HIGHAn improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and creaEPSS 0.3%CVE-2024-41228HIGHA symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges anEPSS 0.3%CVE-2024-6325MEDIUMRockwell Automation Unsecured Private Keys in FactoryTalk® System ServicesEPSS 0.3%CVE-2026-43886HIGHOutline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API AccessEPSS 0.3%CVE-2025-58053MEDIUMGalette has a privilege escalation vulnerabilityEPSS 0.3%CVE-2025-5689HIGHImproper Permission Management in SSH Session HandlingEPSS 0.3%CVE-2025-26705MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.3%CVE-2026-17472CRITICALMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.3%CVE-2026-50295MEDIUMWindows Zero Trust DNS Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-33552LOWNorthern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.EPSS 0.3%CVE-2026-1566HIGHLatePoint <= 5.2.7 - Authenticated (Agent+) Privilege EscalationEPSS 0.3%CVE-2026-15354CRITICALACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' ParameterEPSS 0.3%CVE-2022-42796HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be aEPSS 0.3%CVE-2020-7254HIGHPrivilege escalation in Advanced Threat DefenseEPSS 0.3%