Falhas do tipo CWE-269

2.508 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2020-15934HIGHAn execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. mEPSS 0.2%CVE-2025-32955MEDIUMHarden-Runner Evasion of 'disable-sudo' policyEPSS 0.2%CVE-2026-21983HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2026-11108HIGHInappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalaEPSS 0.2%CVE-2023-52093HIGHAn exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affecteEPSS 0.2%CVE-2020-12615—An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and speciEPSS 0.2%CVE-2024-6677HIGHPrivilege escalation in uberAgentEPSS 0.2%CVE-2022-27677HIGH Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentialEPSS 0.2%CVE-2023-5847MEDIUM Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privilegEPSS 0.2%CVE-2024-36056MEDIUMHw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory via IOCTL 0x9c40649EPSS 0.2%CVE-2024-0049HIGHIn multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privileEPSS 0.2%CVE-2023-21512LOWImproper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notiEPSS 0.2%CVE-2025-43188HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gaEPSS 0.2%CVE-2024-33522MEDIUMPrivilege escalation in Calico CNI install binaryEPSS 0.2%CVE-2023-48418CRITICALUser Build misconfiguration resulting in local escalation of privilegeEPSS 0.2%CVE-2022-32900HIGHA logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be abEPSS 0.2%CVE-2024-21966HIGHA DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resultiEPSS 0.2%CVE-2025-53029LOWVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2023-37925MEDIUMAn improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEEPSS 0.2%CVE-2025-43248HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may EPSS 0.2%