Weaknesses of type CWE-494

187 results

Escalação de Privilégio

É quando um atacante consegue elevar suas permissões no sistema além do que deveria ter acesso — por exemplo, passando de usuário comum para administrador. Acontece porque o software não valida adequadamente quem pode executar certas operações sensíveis, ou confia em dados que podem ser manipulados.

Example

Um aplicativo web que guarda o nível de acesso do usuário em um cookie do lado do cliente (tipo 'role=user') permite que o atacante edite o cookie para 'role=admin' e ganhe acesso a funcionalidades administrativas. Outro caso: um programa Linux que roda com setuid mas não valida argumentos antes de executar comandos do sistema.

How to mitigate

Sempre valide e controle privilégios no servidor/backend, nunca confie em dados do cliente. Use listas de controle de acesso (ACL) ou modelos RBAC bem implementados, e garanta que operações sensíveis exigem reauthenticação ou tokens seguros que não podem ser falsificados.

CVE-2025-11493HIGHSelf-Update Verification Mechanism Process in ConnectWise AutomateEPSS 0.2%CVE-2019-9534The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware imageEPSS 0.2%CVE-2026-82021CRITICALHermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch ReferenceEPSS 0.2%CVE-2024-50696HIGHSunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allEPSS 0.2%CVE-2026-65097HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without intEPSS 0.2%CVE-2024-52331HIGHECOVACS lawnmowers and vacuums deterministic firmware encryption keyEPSS 0.2%CVE-2026-50562CRITICALFastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflowsEPSS 0.2%CVE-2025-53520HIGHEG4 Electronics EG4 Inverters Download of Code Without Integrity CheckEPSS 0.2%CVE-2023-45821MEDIUMIncorrect Docker Hub registry check in Artifact HubEPSS 0.2%CVE-2024-52583HIGHWesHacks code includes links to Leostop tracking spyware infested filesEPSS 0.2%CVE-2026-93534MEDIUMspatie Scotty Self Update SelfUpdater.php update code downloadEPSS 0.2%CVE-2026-57910CRITICALWatchGuard Agent improper authentication allows unauthenticated remote code executionEPSS 0.2%CVE-2025-40604MEDIUMDownload of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifyEPSS 0.2%CVE-2025-9319HIGHA potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under certain conditions.EPSS 0.2%CVE-2026-32148HIGHLockfile checksums not verified in Hex allows dependency integrity bypassEPSS 0.2%CVE-2026-55697HIGHpnpm: Repository-controlled configDependencies can select a pacquet native install engineEPSS 0.2%CVE-2024-43169HIGHIBM Engineering Requirements Management DOORS Next file downloadEPSS 0.2%CVE-2026-79963HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code WEPSS 0.2%CVE-2025-55581HIGHD-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. EPSS 0.2%CVE-2021-47986HIGHParse Server - Unreviewed Code Execution via Malicious Version TagsEPSS 0.2%