Weaknesses of type CWE-280

170 results

Tratamento inadequado de permissões ou privilégios insuficientes

Ocorre quando uma aplicação não valida ou não rejeita adequadamente requisições de usuários que carecem de permissões necessárias para executar uma ação. Em vez de negar o acesso, o sistema permite a operação, expõe informações sensíveis ou executa funções críticas sem verificar direitos. O risco é perda de confidencialidade, integridade ou disponibilidade dos dados.

Example

Uma API REST que deleta registros de usuários verifica apenas se o token JWT é válido, mas não confirma se o usuário autenticado tem permissão 'admin' para deletar. Qualquer usuário logado consegue remover dados de outros usuários ou do sistema.

How to mitigate

Implemente verificações de autorização granulares em cada endpoint ou função sensível, validando não apenas autenticação, mas o nível de privilégio necessário. Use o padrão de controle de acesso baseado em papéis (RBAC) ou atributos (ABAC) e teste permissões antes de executar operações críticas.

CVE-2024-47767MEDIUMTuleap lists trackers in the quick add actions of the backlog without any permissions checkEPSS 0.4%CVE-2025-6573CRITICALGPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/OverwriteEPSS 0.4%CVE-2023-2020MEDIUMUnauthorized scheduling of downtimes via REST APIEPSS 0.4%CVE-2025-8109HIGHGPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operationEPSS 0.4%CVE-2025-50170HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-46874CRITICALRuijie Reyee OS Improper Handling of Insufficient Permissions or PrivilegesEPSS 0.4%CVE-2025-49731LOWMicrosoft Teams Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-36112MEDIUMNautobot dynamic-group-members doesn't enforce permission restrictions on member objectsEPSS 0.4%CVE-2025-67848HIGHMoodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.EPSS 0.4%CVE-2022-34368MEDIUMDell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Permissions or PrivilegEPSS 0.4%CVE-2024-4468MEDIUMSalon booking system <= 9.9 - Missing AuthorizationEPSS 0.4%CVE-2024-0015HIGHIn convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. EPSS 0.4%CVE-2025-22256MEDIUMA improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1EPSS 0.4%CVE-2026-41566CRITICALApache Kvrocks: Improper permission for the APPLYBATCH commandEPSS 0.4%CVE-2023-52537HIGHVulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will afEPSS 0.4%CVE-2025-27024MEDIUMImproper File Access in Infinera G42EPSS 0.4%CVE-2024-46988MEDIUMTuleap does not properly check permissions for email notifications in trackersEPSS 0.4%CVE-2025-24029MEDIUMArtifact permissions are not verified in the Cross Tracker Search widget in TuleapEPSS 0.4%CVE-2024-30418HIGHVulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability wiEPSS 0.4%CVE-2026-73239MEDIUMApache Allura: Missing permission checks IDOREPSS 0.3%