Falhas do tipo CWE-269

2.508 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2025-55627MEDIUMInsufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows auEPSS 0.2%CVE-2023-48419CRITICALAn attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in EoPEPSS 0.2%CVE-2025-53030MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2025-57396MEDIUMTandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which reEPSS 0.2%CVE-2024-41949LOWbiscuit-rust vulnerable to public key confusion in third party blockEPSS 0.2%CVE-2024-40781HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A localEPSS 0.2%CVE-2023-45083MEDIUMHyperCloud: "admin" and "serveradmin" users can be deletedEPSS 0.2%CVE-2024-28813HIGHAn issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker EPSS 0.2%CVE-2025-26706MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.2%CVE-2025-36890CRITICALElevation of PrivilegeEPSS 0.2%CVE-2022-32949HIGHThis issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16. An app may be able to execute aEPSS 0.2%CVE-2026-83463HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.2%CVE-2020-7274MEDIUMENS elevated permissions vulnerabilityEPSS 0.2%CVE-2025-26704MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.2%CVE-2024-40802HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A localEPSS 0.2%CVE-2025-53914HIGHCalix GigaCenter ONT (Broadcom SoC) - Excessive PrivilegesEPSS 0.2%CVE-2024-38499HIGHImproper Privilege Management Vulnerability in CA Client Automation 14.5EPSS 0.2%CVE-2023-32426—A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to gain root privileges.EPSS 0.2%CVE-2025-39202HIGHA vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can seeEPSS 0.2%CVE-2025-53027HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%