Weaknesses of type CWE-268

22 results

Encadeamento de Privilégios

É quando um aplicativo ou sistema concede acesso a recursos sensíveis aproveitando uma sequência de operações com privilégios, sem validar adequadamente cada etapa. Um atacante explora essa cadeia para elevar seus privilégios além do que deveria ter, combinando múltiplas ações de menor risco para ganhar acesso indevido.

Example

Um aplicativo web permite que um usuário comum visualize seu próprio perfil (operação 1), depois modifique dados através de um endpoint que não valida permissões (operação 2), e finalmente acesse um painel administrativo porque o sistema confiou nas operações anteriores sem revalidar (operação 3). O atacante encadeou essas três ações para virar admin.

How to mitigate

Valide permissões explicitamente em cada operação sensível, não confie em verificações anteriores. Use controle de acesso baseado em papéis (RBAC) ou atributos (ABAC) de forma granular, e implemente logs detalhados de quem acessou o quê para detectar padrões suspeitos.

CVE-2025-49741HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 3.4%CVE-2019-3844MEDIUMIt was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, whichEPSS 0.9%CVE-2024-1250MEDIUMPrivilege Chaining in GitLabEPSS 0.5%CVE-2024-1299MEDIUMPrivilege Chaining in GitLabEPSS 0.5%CVE-2023-20194MEDIUMA vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operatinEPSS 0.5%CVE-2022-1003LOWSysadmin can override existing configs & bypass restrictions like EnableUploadsEPSS 0.5%CVE-2024-4877HIGHOpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI cEPSS 0.4%CVE-2025-36124MEDIUMIBM WebSphere Application Server Liberty bypass securityEPSS 0.4%CVE-2026-3888HIGHLocal Privilege Escalation in snapdEPSS 0.4%CVE-2023-0759MEDIUMPrivilege Chaining in cockpit-hq/cockpitEPSS 0.3%CVE-2023-5839HIGHPrivilege Chaining in hestiacp/hestiacpEPSS 0.3%CVE-2023-0971CRITICALCommand Authentication Bypass in Z/IP GatewayEPSS 0.3%CVE-2025-32955MEDIUMHarden-Runner Evasion of 'disable-sudo' policyEPSS 0.2%CVE-2023-2250MEDIUMA flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registrationEPSS 0.2%CVE-2025-0889HIGHPrivilege Management for Windows – Elevation of PrivilegeEPSS 0.2%CVE-2025-2903HIGHPrivilege Chaining in DelphixEPSS 0.2%CVE-2024-47045HIGHPrivilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepEPSS 0.1%CVE-2025-7973HIGHRockwell Automation FactoryTalk® ViewPoint Privilege Escalation VulnerabilityEPSS 0.1%CVE-2025-2297HIGHPrivilege Management for Windows - Elevation of PrivilegeEPSS 0.1%CVE-2025-20112MEDIUMCisco Unified Communications Products Privilege Escalation VulnerabilityEPSS 0.1%