Weaknesses of type CWE-494

187 results

Escalação de Privilégio

É quando um atacante consegue elevar suas permissões no sistema além do que deveria ter acesso — por exemplo, passando de usuário comum para administrador. Acontece porque o software não valida adequadamente quem pode executar certas operações sensíveis, ou confia em dados que podem ser manipulados.

Example

Um aplicativo web que guarda o nível de acesso do usuário em um cookie do lado do cliente (tipo 'role=user') permite que o atacante edite o cookie para 'role=admin' e ganhe acesso a funcionalidades administrativas. Outro caso: um programa Linux que roda com setuid mas não valida argumentos antes de executar comandos do sistema.

How to mitigate

Sempre valide e controle privilégios no servidor/backend, nunca confie em dados do cliente. Use listas de controle de acesso (ACL) ou modelos RBAC bem implementados, e garanta que operações sensíveis exigem reauthenticação ou tokens seguros que não podem ser falsificados.

CVE-2025-10539MEDIUMImproper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking AppEPSS 0.2%CVE-2021-47987HIGHParse Server - Arbitrary Code Execution via Malicious Version TagsEPSS 0.2%CVE-2023-24503HIGH Electra Smart Kit for Split AC – Adjacent attacker may cause the unit to load unauthorized FWEPSS 0.2%CVE-2023-24500HIGH Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FWEPSS 0.2%CVE-2026-53970HIGHZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rbEPSS 0.2%CVE-2026-22816HIGHGradle fails to disable repositories which can expose builds to malicious artifactsEPSS 0.2%CVE-2023-28818MEDIUMAn issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that couEPSS 0.2%CVE-2024-28850HIGHWP Crontrol possible RCE when combined with a pre-conditionEPSS 0.2%CVE-2026-22306CRITICALCritical flaw impacting OZOLS ERP's automatic update channelEPSS 0.2%CVE-2025-52263HIGHAn issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers toEPSS 0.2%CVE-2021-35532Firmware upload verification bypass in TXpert Hub CoreTec 4EPSS 0.2%CVE-2024-47192MEDIUMAn issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files thEPSS 0.2%CVE-2026-42575HIGHapko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)EPSS 0.2%CVE-2026-22865HIGHGradle's failure to disable repositories failing to answer can expose builds to malicious artifactsEPSS 0.2%CVE-2024-48974CRITICALLife2000 Ventilator does not perform proper file integrity checks when adopting firmware updatesEPSS 0.2%CVE-2024-33660MEDIUMPotential Firmware update without integrity checkEPSS 0.1%CVE-2024-54126HIGHInsufficient Integrity Verification Vulnerability in TP-Link Archer C50EPSS 0.1%CVE-2026-20056MEDIUMCisco Secure Web Appliance TBD Bypass VulnerabilityEPSS 0.1%CVE-2026-81052MEDIUMDell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attackeEPSS 0.1%CVE-2026-1878MEDIUMAn Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SEPSS 0.1%