Weaknesses of type CWE-264

299 results

Controle de acesso e privilégios inadequado

A fraqueza ocorre quando a aplicação não valida corretamente quem pode fazer o quê, permitindo que usuários acessem recursos ou executem operações acima de seus privilégios. Isso acontece porque as verificações de autorização são ausentes, incompletas ou contornáveis, expondo dados sensíveis ou permitindo ações não autorizadas.

Example

Um usuário comum consegue listar ou modificar dados de outros usuários alterando um ID na URL (ex: /profile/123 → /profile/999) sem que o servidor valide se ele tem permissão para acessar aquele perfil. Ou um atacante executa ações administrativas porque a aplicação só verifica autenticação, não autorização.

How to mitigate

Implemente verificações de autorização em toda operação sensível: valide não apenas se o usuário está logado, mas se ele tem permissão específica para aquele recurso. Use listas de controle de acesso (ACL), roles bem definidas e princípio do menor privilégio. Teste sistematicamente tentativas de escalação e acesso lateral entre usuários.

CVE-2020-7257HIGHPrivilege Escalation vulnerability through Symbolic links in ENSEPSS 0.3%CVE-2020-7259MEDIUMUnsigned executable vulnerability in ENS can be used to bypass intended self-protection rulesEPSS 0.3%CVE-2026-49310HIGHPermission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service EPSS 0.3%CVE-2024-22452HIGHDell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potEPSS 0.2%CVE-2020-7255LOWPrivilege Escalation vulnerability  in ENSEPSS 0.2%CVE-2021-28497MEDIUMIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell mEPSS 0.2%CVE-2022-23714—A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which EPSS 0.2%CVE-2023-52955MEDIUMVulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause feEPSS 0.2%CVE-2019-19107MEDIUMABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Information ExposureEPSS 0.2%CVE-2026-6117MEDIUMAstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandboxEPSS 0.2%CVE-2024-54104MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2020-1630MEDIUMJunos OS: Privilege escalation vulnerability in dual REs, VC or HA cluster may allow unauthorized configuration change.EPSS 0.2%CVE-2020-11933HIGHlocal snapd exploit through cloud-initEPSS 0.2%CVE-2024-56440MEDIUMPermission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perfEPSS 0.2%CVE-2024-45442MEDIUMVulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability wEPSS 0.2%CVE-2018-6674MEDIUMPrivilege escalation vulnerability in McAfee VSE when McTray run with elevated privilegesEPSS 0.2%CVE-2024-54103MEDIUMVulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidEPSS 0.2%CVE-2020-7263MEDIUMENS configuration can be edited by attacker with local administrator permissionsEPSS 0.2%CVE-2024-20370MEDIUMA vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco EPSS 0.2%CVE-2023-52721MEDIUMThe WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confideEPSS 0.2%