Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2020-7330HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP) trialEPSS 0.3%CVE-2026-61013MEDIUMVulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-70443MEDIUMJenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackerEPSS 0.3%CVE-2026-87164HIGHVulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that EPSS 0.3%CVE-2026-16366HIGHPrivilege escalation in the DOM: Navigation componentEPSS 0.3%CVE-2026-73842CRITICALOpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutationEPSS 0.3%CVE-2022-32826HIGHAn authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, EPSS 0.3%CVE-2025-25872MEDIUMAn issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions functionEPSS 0.3%CVE-2025-5494LOWPrivilege EscalationEPSS 0.3%CVE-2025-20346MEDIUMCisco Catalyst Center Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-56733HIGHZammad: Incorrect Authorization and Improper Privilege ManagementEPSS 0.3%CVE-2026-60371HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2026-75924HIGHManaged-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants cluster-wide secret read/write and csr approvalEPSS 0.3%CVE-2025-31284MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to EPSS 0.3%CVE-2025-31282MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administratEPSS 0.3%CVE-2025-31285MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator EPSS 0.3%CVE-2025-31283MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administratorEPSS 0.3%CVE-2023-24483HIGHPrivilege Escalation to NT AUTHORITY\SYSTEM on the vulnerable VDAEPSS 0.3%CVE-2024-45752HIGHlogiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus seEPSS 0.3%CVE-2026-44987LOWSysReptor: Privilege Escalation from User Admin to SuperuserEPSS 0.3%