Falhas do tipo CWE-269

2.508 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2024-44439MEDIUMAn issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allowsEPSS 0.2%CVE-2025-43249HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An aEPSS 0.2%CVE-2025-43248HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may EPSS 0.2%CVE-2022-43533HIGH A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A suEPSS 0.2%CVE-2023-5960MEDIUMAn improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VEPSS 0.2%CVE-2025-36891HIGHElevation of privilegeEPSS 0.2%CVE-2021-23887HIGHPrivilege escalation in McAfee DLP Endpoint for WindowsEPSS 0.2%CVE-2025-27644HIGHVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-0EPSS 0.2%CVE-2021-27445HIGHMesa Labs AmegaView Improper Privilege ManagementEPSS 0.2%CVE-2024-28241HIGHGlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folderEPSS 0.2%CVE-2024-44540MEDIUMUbiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART DeEPSS 0.2%CVE-2024-43446LOWImproper check of permissions in Generic InterfaceEPSS 0.2%CVE-2026-84358MEDIUMImproper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2024-12786HIGHX1a0He Adobe Downloader XPC Service com.x1a0he.macOS.Adobe-Downloader.helper shouldAcceptNewConnection privileges managementEPSS 0.2%CVE-2021-22733—Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access EPSS 0.2%CVE-2026-16401HIGHPrivilege escalation in the Data Loss Prevention componentEPSS 0.2%CVE-2025-50064MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.2%CVE-2024-6151HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2025-31243HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS VenturEPSS 0.2%CVE-2023-5650MEDIUMAn improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmEPSS 0.2%