Falhas do tipo CWE-269

2.507 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2026-46424MEDIUMBudibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 HourEPSS 0.2%CVE-2021-43768MEDIUMIn Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface runnEPSS 0.2%CVE-2025-0358HIGHDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration fraEPSS 0.2%CVE-2023-3514HIGHRazerCentralSerivce Unsafe Named Pipe Permission Escalation of Privilege VulnerabilityEPSS 0.2%CVE-2023-25647MEDIUMPermission and Access Control Vulnerability in Some ZTE Mobile PhonesEPSS 0.2%CVE-2025-57759MEDIUMContao has improper privilege management for page and article fieldsEPSS 0.2%CVE-2025-26703MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.2%CVE-2020-7281HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.2%CVE-2024-22237HIGHAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for NetworksEPSS 0.2%CVE-2026-100586HIGHOpenClaw Codex before 2026.7.1 Authorization Bypass via BindEPSS 0.2%CVE-2025-6759HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2020-7273MEDIUMAutorun registry bypassEPSS 0.2%CVE-2021-3809HIGHPotential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary EPSS 0.2%CVE-2021-3808HIGHPotential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary EPSS 0.2%CVE-2025-27468HIGHWindows Kernel-Mode Driver Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2023-52431HIGHThe Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form valEPSS 0.2%CVE-2021-31359HIGHJunos OS and Junos OS Evolved: Local Privilege Escalation vulnerabilityEPSS 0.2%CVE-2022-38774HIGHAn issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivilegEPSS 0.2%CVE-2025-36904CRITICALWLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.EPSS 0.2%CVE-2026-73779HIGHAuthentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CXEPSS 0.2%