Weaknesses of type CWE-264

299 results

Controle de acesso e privilégios inadequado

A fraqueza ocorre quando a aplicação não valida corretamente quem pode fazer o quê, permitindo que usuários acessem recursos ou executem operações acima de seus privilégios. Isso acontece porque as verificações de autorização são ausentes, incompletas ou contornáveis, expondo dados sensíveis ou permitindo ações não autorizadas.

Example

Um usuário comum consegue listar ou modificar dados de outros usuários alterando um ID na URL (ex: /profile/123 → /profile/999) sem que o servidor valide se ele tem permissão para acessar aquele perfil. Ou um atacante executa ações administrativas porque a aplicação só verifica autenticação, não autorização.

How to mitigate

Implemente verificações de autorização em toda operação sensível: valide não apenas se o usuário está logado, mas se ele tem permissão específica para aquele recurso. Use listas de controle de acesso (ACL), roles bem definidas e princípio do menor privilégio. Teste sistematicamente tentativas de escalação e acesso lateral entre usuários.

CVE-2020-1619MEDIUMJunos OS: QFX10K Series, EX9200 Series, MX Series, PTX Series: Privilege escalation vulnerability in NG-RE.EPSS 0.3%CVE-2017-12261—A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated,EPSS 0.3%CVE-2026-76412HIGHCisco Secure Firewall Management Center Software Authenticated Privilege Escalation to Root VulnerabilityEPSS 0.3%CVE-2020-3208MEDIUMCisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers Image Verification Bypass VulnerabilityEPSS 0.3%CVE-2017-6623—A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance couldEPSS 0.3%CVE-2019-1803HIGHCisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Root Privilege Escalation VulnerabilityEPSS 0.3%CVE-2019-13013—Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helperEPSS 0.3%CVE-2026-6224MEDIUMnocobase plugin-workflow-javascript Vm.js createSafeConsole sandboxEPSS 0.3%CVE-2020-7254HIGHPrivilege escalation in Advanced Threat DefenseEPSS 0.3%CVE-2025-5874LOWRedash getattr python.py run_query sandboxEPSS 0.3%CVE-2023-39387—Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-uEPSS 0.3%CVE-2023-42005HIGHIBM Db2 on Cloud Pak for Data privilege escalationEPSS 0.3%CVE-2020-3180HIGHCisco SD-WAN Solution Software Static Credentials VulnerabilityEPSS 0.3%CVE-2019-3637MEDIUMPrivilege Escalation vulnerability in FRP 5.x earlier than 5.1.0.209EPSS 0.3%CVE-2020-3530HIGHCisco IOS XR Authenticated User Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-52106MEDIUMVulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability EPSS 0.3%CVE-2019-19100HIGHPrivilege escalation via B&R Automation Studio upgrade serviceEPSS 0.3%CVE-2024-56444HIGHCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.3%CVE-2026-18593MEDIUMvxcontrol PentAGI Tool Management Protocol pentester.tmpl sandboxEPSS 0.3%CVE-2020-8092LOWPrivilege escalation in Bitdefender AV for MacEPSS 0.3%