Weaknesses of type CWE-267

68 results

Privilégio definido com ações inseguras

Quando uma aplicação concede um nível de privilégio ou papel (role) que permite executar ações perigosas sem validação ou proteção adequada. O desenvolvedor cria uma função administrativa ou de confiança, mas não implementa verificações suficientes antes de deixar que essa função faça operações críticas como deletar dados, alterar configurações de segurança ou acessar informações sensíveis.

Example

Um painel de admin que deixa qualquer usuário com role 'gerente' deletar contas de clientes sem auditoria, confirmação em dois passos ou log de quem deletou — permitindo que um gerente desgrenhado ou comprometido cause dano massivo sem deixar rastreamento claro ou sem possibilidade de reverter.

How to mitigate

Separe privilégios por granularidade (ex: 'deletar_conta' diferente de 'editar_perfil'); exija validações extras para ações destrutivas (confirmação, segundo fator, revisão); implemente auditoria completa de quem fez o quê; use o princípio do menor privilégio — nunca dê mais permissão que o estritamente necessário para a função.

CVE-2017-2616MEDIUMA race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attackEPSS 0.3%CVE-2026-2460HIGHA vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by usingEPSS 0.3%CVE-2026-27314HIGHApache Cassandra: Privilege escalation via ADD IDENTITY authorization bypassEPSS 0.3%CVE-2025-36255HIGHDS8900F and DS8A00 Privilege EscalationEPSS 0.3%CVE-2024-7571HIGHIncorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.EPSS 0.3%CVE-2024-39866HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to uploEPSS 0.2%CVE-2026-0945MEDIUMRole Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002EPSS 0.2%CVE-2024-47906HIGHExcessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before versiEPSS 0.2%CVE-2024-8539HIGHImproper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configEPSS 0.2%CVE-2024-9842HIGHIncorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary foldersEPSS 0.2%CVE-2025-62589HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-62588HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2026-81161LOWContent Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107EPSS 0.2%CVE-2025-62641HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-62590HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-2903HIGHPrivilege Chaining in DelphixEPSS 0.2%CVE-2025-62587HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2023-44218HIGH A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system EPSS 0.2%CVE-2025-62591MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2024-5623MEDIUMUntrusted search path vulnerability in B&R APROLEPSS 0.2%