Weaknesses of type CWE-266

1,176 results

Atribuição incorreta de privilégios

Acontece quando uma aplicação ou sistema concede permissões (privilégios) a um usuário, processo ou recurso de forma errada — atribuindo mais acesso do que deveria ou permitindo operações que não deveriam estar disponíveis. O risco é que um atacante ou usuário sem autorização consiga executar ações críticas, acessar dados sensíveis ou elevar seus privilégios no sistema.

Example

Um aplicativo cria um arquivo de configuração com permissões 0666 (leitura e escrita para todos) quando deveria ser 0600 (apenas dono); ou uma API expõe endpoints administrativos sem verificar se o usuário logado é realmente um admin, permitindo que qualquer pessoa autenticada delete dados ou mude configurações.

How to mitigate

Implemente controle de acesso baseado em papéis (RBAC) ou atributos (ABAC), verificando permissões explicitamente antes de cada operação crítica. Defina permissões padrão restritivas (deny-by-default), revise regularmente quem tem acesso a quê, e use ferramentas de análise estática para detectar atribuições de privilégio hardcoded ou inconsistentes no código.

CVE-2025-26425MEDIUMIn multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This couEPSS 0.1%CVE-2026-20110MEDIUMA vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) conditioEPSS 0.1%CVE-2023-21269—In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL byEPSS 0.1%CVE-2025-48528MEDIUMIn multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalationEPSS 0.1%CVE-2025-32747MEDIUMDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with localEPSS 0.1%CVE-2025-48526MEDIUMIn createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profEPSS 0.1%CVE-2023-20957HIGHIn onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This couldEPSS 0.1%CVE-2026-21425MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect privilege assignment vulneraEPSS 0.1%CVE-2024-49731MEDIUMIn apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new Pixel Watch due to aEPSS 0.1%CVE-2024-34738HIGHIn multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due EPSS 0.1%CVE-2025-22415MEDIUMIn android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local escalation of privilEPSS 0.1%CVE-2025-2713MEDIUMImproper File Permission Handling in Google gVisor runscEPSS 0.1%CVE-2026-100883MEDIUMKrayin laravel-crm acl.php access controlEPSS —CVE-2026-93540MEDIUMFleet applies namespace labels and annotations without the bundle's service account privilegesEPSS —CVE-2026-101053MEDIUMThinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access controlEPSS —CVE-2026-101054MEDIUMThinkware U3000 TCP Service wpa_supplicant.conf get_file access controlEPSS —