Weaknesses of type CWE-269

2,488 results

Gestão inadequada de privilégios

A aplicação falha em atribuir, modificar, rastrear ou validar corretamente os privilégios de um usuário ou processo, permitindo que ele acesse ou execute operações além do que deveria. Isso acontece quando o controle de acesso é incompleto, inconsistente ou ausente em pontos críticos do código.

Example

Um usuário comum consegue editar perfis de administrador porque a aplicação verifica permissões apenas na interface web, mas não na API backend; ou um processo que perde privilégios elevados durante sua execução consegue executar ações sensíveis sem validação adicional.

How to mitigate

Implemente validação de privilégios em toda camada de negócio (não apenas UI), use modelos de controle de acesso consistentes (RBAC, ABAC), valide permissões antes de cada operação sensível e teste cenários de escalação de privilégio em testes de segurança.

CVE-2024-32418CRITICALAn issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.EPSS 1.1%CVE-2023-26604HIGHsystemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in whichEPSS 1.1%CVE-2021-33538HIGHWEIDMUELLER: WLAN devices affected by improper access control vulnerabilityEPSS 1.0%CVE-2022-32536HIGHPrivilege EscalationEPSS 1.0%CVE-2003-5001MEDIUMISS BlackICE PC Protection Cross Site Scripting Detection privileges managementEPSS 1.0%CVE-2024-14004HIGHNagios XI < 2024R1.2 Privilege Escalation via NagVis Configuration (nagvis.conf)EPSS 1.0%CVE-2023-25133CRITICALImproper privilege management vulnerability in CyberPower PowerPanel BusinessEPSS 1.0%CVE-2021-23874HIGHMcAfee Total Protection (MTP) privilege escalation vulnerabilityEPSS 1.0%KEVCVE-2018-25041MEDIUMuTorrent JSON RPC Server privileges managementEPSS 1.0%CVE-2021-37627HIGHPrivilege escalation via form generatorEPSS 1.0%CVE-2020-7305MEDIUMDLP ePO extension - Privilege escalationEPSS 1.0%CVE-2024-45496CRITICALOpenshift-controller-manager: elevated build pods can lead to node compromise in openshiftEPSS 1.0%CVE-2017-20021MEDIUMSolare Solar-Log File Upload privileges managementEPSS 1.0%CVE-2020-12527MEDIUMImproper Access Validation in products of MB connect line and HelmholzEPSS 1.0%CVE-2023-22331HIGHUse of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to altEPSS 1.0%CVE-2024-34331CRITICALA lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted mEPSS 1.0%CVE-2023-4293HIGHPremium Packages - Sell Digital Products Securely <= 5.7.4 - Arbitrary User Meta Update to Authenticated (Subscriber+) Privilege EscalationEPSS 1.0%CVE-2022-48341—ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain SyEPSS 1.0%CVE-2023-43457—An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/adminEPSS 1.0%CVE-2018-25044MEDIUMuTorrent Guest Account privileges managementEPSS 1.0%