Weaknesses of type CWE-266

1,174 results

Atribuição incorreta de privilégios

Acontece quando uma aplicação ou sistema concede permissões (privilégios) a um usuário, processo ou recurso de forma errada — atribuindo mais acesso do que deveria ou permitindo operações que não deveriam estar disponíveis. O risco é que um atacante ou usuário sem autorização consiga executar ações críticas, acessar dados sensíveis ou elevar seus privilégios no sistema.

Example

Um aplicativo cria um arquivo de configuração com permissões 0666 (leitura e escrita para todos) quando deveria ser 0600 (apenas dono); ou uma API expõe endpoints administrativos sem verificar se o usuário logado é realmente um admin, permitindo que qualquer pessoa autenticada delete dados ou mude configurações.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC) ou atributos (ABAC), verificando permissões explicitamente antes de cada operação crítica. Defina permissões padrão restritivas (deny-by-default), revise regularmente quem tem acesso a quê, e use ferramentas de análise estática para detectar atribuições de privilégio hardcoded ou inconsistentes no código.

CVE-2026-11533MEDIUMimvks786 student_management_system Student Deletion Endpoint see.php improper authorizationEPSS 0.2%CVE-2026-10284MEDIUMDevaslanPHP project-management Livewire ViewTicket.php doDeleteComment improper authorizationEPSS 0.2%CVE-2024-57967MEDIUMPVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mEPSS 0.2%CVE-2026-10285MEDIUMDevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorizationEPSS 0.2%CVE-2026-10218MEDIUMnextlevelbuilder GoClaw evolution_handlers.go auth improper authorizationEPSS 0.2%CVE-2026-10282MEDIUMBottelet DaybydayCRM DocumentsController.php view improper authorizationEPSS 0.2%CVE-2026-10294MEDIUMPackageKit API pk-transaction.c g_file_test improper authorizationEPSS 0.2%CVE-2023-47140MEDIUMIBM CICS Transaction Gateway improper access controlsEPSS 0.2%CVE-2025-2850MEDIUMGL.iNet GL-A1300 Slate Plus Download Interface improper authorizationEPSS 0.2%CVE-2020-10728—A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissioEPSS 0.2%CVE-2026-10070MEDIUMmacrozheng mall Super Admin Password update improper authorizationEPSS 0.2%CVE-2020-35514—An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a rEPSS 0.2%CVE-2024-33503MEDIUMA improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FoEPSS 0.2%CVE-2026-1411MEDIUMBeetel 777VR1 UART access controlEPSS 0.2%CVE-2024-12786HIGHX1a0He Adobe Downloader XPC Service com.x1a0he.macOS.Adobe-Downloader.helper shouldAcceptNewConnection privileges managementEPSS 0.2%CVE-2026-11494MEDIUMTOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violationEPSS 0.2%CVE-2026-11438MEDIUMtheonedev projects improper authorizationEPSS 0.2%CVE-2026-10693MEDIUMSourceCodester Online Boat Reservation System Administrative Endpoint improper authorizationEPSS 0.2%CVE-2026-11439MEDIUMtheonedev Parent Project projects improper authorizationEPSS 0.2%CVE-2026-11440MEDIUMtheonedev REST API default-branch improper authorizationEPSS 0.2%