Falhas do tipo CWE-269

2.509 resultados

Controle de privilégios inadequado ou ausente

A aplicação falha em validar, atribuir ou manter corretamente os privilégios de um usuário ou processo, permitindo que ele acesse recursos ou execute ações além do que deveria. Isso ocorre quando o controle de acesso é ausente, inconsistente ou não é verificado em todos os pontos críticos do código.

Exemplo

Um usuário comum consegue acessar um endpoint de administração porque a aplicação não valida se ele tem permissão, ou um processo web consegue ler arquivos do sistema que deveriam estar restritos apenas ao root — em ambos os casos, o código simplesmente não conferiu os privilégios antes de executar a operação.

Como mitigar

Implemente verificações de autorização em cada operação sensível (acesso a dados, mudança de configurações, etc.), use um modelo de privilégios bem definido (RBAC, ABAC), e verifique permissões de forma centralizada — nunca confie apenas em frontend ou em ausência de validação. Mantenha auditoria de quem fez o quê e quando.

CVE-2022-39953HIGHA improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1EPSS 0.2%CVE-2026-11295HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege esEPSS 0.2%CVE-2024-40460HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXEEPSS 0.2%CVE-2024-40458HIGHAn issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.EPSS 0.2%CVE-2021-24038—Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged pEPSS 0.2%CVE-2024-40462HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE componentEPSS 0.2%CVE-2023-6804MEDIUMImproper Privilege Management allows for arbitrary workflows to be runEPSS 0.2%CVE-2025-64487HIGHOutline is vulnerable to privilege escalation vulnerability in document sharingEPSS 0.2%CVE-2024-40461HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE componentEPSS 0.2%CVE-2024-23457HIGHAnti-tampering can be disabled with uninstall password enforcedEPSS 0.2%CVE-2024-40459HIGHAn issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager functionEPSS 0.2%CVE-2025-1424HIGHPrivilege Escalation Through SUID Binary and Developer ModeEPSS 0.2%CVE-2025-1732MEDIUMAn improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlieEPSS 0.2%CVE-2025-12425CRITICALLocal Privilege EscalationEPSS 0.2%CVE-2023-25535HIGH Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerabilityEPSS 0.2%CVE-2025-70795MEDIUMSTProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminEPSS 0.2%CVE-2023-24491HIGH A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with accEPSS 0.2%CVE-2026-33727MEDIUMPi-hole has a Local Privilege Escalation (post-compromise, pihole -> root).EPSS 0.2%CVE-2026-22804HIGHTermix has a Stored XSS in File Manager leading to Local File Inclusion (LFI) in Electron and Session Hijacking in BrowserEPSS 0.2%CVE-2018-9375HIGHIn multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confusEPSS 0.2%