Falhas do tipo CWE-269

2.488 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2017-0934Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection ofEPSS 1.3%CVE-2020-8258Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15EPSS 1.3%CVE-2026-8206CRITICALKirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'EPSS 1.3%CVE-2023-48902CRITICALAn issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car dEPSS 1.3%CVE-2017-0935Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection EPSS 1.3%CVE-2020-8021MEDIUMunauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build ServiceEPSS 1.3%CVE-2022-43138CRITICALDolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.EPSS 1.3%CVE-2022-29218HIGHUnauthorized takeover for new versions of some platform-specific gemsEPSS 1.3%CVE-2021-27657HIGHMetasys Improper Privilege ManagementEPSS 1.2%CVE-2026-7467HIGHRead More & Accordion <= 3.5.7 - Privilege Escalation via importDataEPSS 1.2%CVE-2024-31141MEDIUMApache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProviderEPSS 1.2%CVE-2023-41954HIGHWordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerabilityEPSS 1.2%CVE-2021-28814HIGHImproper Access Control Vulnerability in HelpdeskEPSS 1.2%CVE-2017-0932Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation EPSS 1.2%CVE-2021-31581HIGHAkkadian Provisioning Manager Engine (PME) Shell Escape via 'vi' editor interfaceEPSS 1.2%CVE-2022-20361MEDIUMIn btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth StaEPSS 1.2%CVE-2022-42735HIGHApache ShenYu Admin ultra viresEPSS 1.2%CVE-2020-7509A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow aEPSS 1.2%CVE-2018-19635CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.EPSS 1.2%CVE-2022-39395CRITICALVela Insecure DefaultsEPSS 1.2%