Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-79276MEDIUMImproper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering EPSS 0.3%CVE-2024-23276HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An EPSS 0.3%CVE-2019-3585HIGHVSE Escalation of Privileges through Alert pop-up windowEPSS 0.3%CVE-2022-43308HIGHINTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.EPSS 0.3%CVE-2023-23429MEDIUM Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2026-48926MEDIUMJenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with OEPSS 0.3%CVE-2026-7778MEDIUMrunZero Platform dashboard configuration exposureEPSS 0.3%CVE-2026-48923MEDIUMJenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackersEPSS 0.3%CVE-2026-77003LOWContent Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_content_maskEPSS 0.3%CVE-2026-2375MEDIUMApp Builder – Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' ParameterEPSS 0.3%CVE-2018-10502—This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 4.2.18.EPSS 0.3%CVE-2026-30888LOWDiscourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpointEPSS 0.3%CVE-2025-26707MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.3%CVE-2020-7311HIGHPrivilege Escalation vulnerability in MA for WindowsEPSS 0.3%CVE-2026-16379HIGHPrivilege escalation in the DOM: Content Processes componentEPSS 0.3%CVE-2026-61549CRITICALWoodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backendEPSS 0.3%CVE-2026-16365HIGHPrivilege escalation in the DOM: Workers componentEPSS 0.3%CVE-2026-1750HIGHEcwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_accessEPSS 0.3%CVE-2023-52114HIGHData confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.EPSS 0.3%CVE-2026-92015HIGHPrivilege escalation in the WebExtensions componentEPSS 0.3%