Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2024-21141HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PrioEPSS 0.3%CVE-2025-64436MEDIUMKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between NodesEPSS 0.3%CVE-2025-22621MEDIUMPrivilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAREPSS 0.3%CVE-2024-3507HIGHPrivilege escalation vulnerability in LunarEPSS 0.3%CVE-2024-31320HIGHIn setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation dEPSS 0.3%CVE-2024-27207CRITICALExported broadcast receivers allowing malicious apps to bypass broadcast protection.EPSS 0.3%CVE-2024-27826HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma EPSS 0.3%CVE-2026-83170HIGHVulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are aEPSS 0.3%CVE-2021-25657HIGHAvaya IP Office Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-50066LOWVulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-1EPSS 0.3%CVE-2024-32849HIGHTrend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionaEPSS 0.3%CVE-2024-37364MEDIUMAriane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensiEPSS 0.3%CVE-2026-17952HIGHInappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious eEPSS 0.3%CVE-2025-12405HIGHUnauthorized access through stored credentials in Looker StudioEPSS 0.3%CVE-2022-32782MEDIUMThis issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able tEPSS 0.3%CVE-2020-27352CRITICALWhen generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result sEPSS 0.3%CVE-2023-38614MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be EPSS 0.3%CVE-2026-12448HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege eEPSS 0.3%CVE-2026-92017HIGHPrivilege escalation in the DOM: Service Workers componentEPSS 0.3%CVE-2022-38777HIGHAn issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate thEPSS 0.3%