Weaknesses of type CWE-494

187 results

Escalação de Privilégio

É quando um atacante consegue elevar suas permissões no sistema além do que deveria ter acesso — por exemplo, passando de usuário comum para administrador. Acontece porque o software não valida adequadamente quem pode executar certas operações sensíveis, ou confia em dados que podem ser manipulados.

Example

Um aplicativo web que guarda o nível de acesso do usuário em um cookie do lado do cliente (tipo 'role=user') permite que o atacante edite o cookie para 'role=admin' e ganhe acesso a funcionalidades administrativas. Outro caso: um programa Linux que roda com setuid mas não valida argumentos antes de executar comandos do sistema.

How to mitigate

Sempre valide e controle privilégios no servidor/backend, nunca confie em dados do cliente. Use listas de controle de acesso (ACL) ou modelos RBAC bem implementados, e garanta que operações sensíveis exigem reauthenticação ou tokens seguros que não podem ser falsificados.

CVE-2025-15575MEDIUMMissing Firmware Authenticity Checks in Solax Power Pocket WiFi modelsEPSS 0.1%CVE-2026-49450HIGHJoplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherNameEPSS 0.1%CVE-2025-55310HIGHAn issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replaEPSS 0.1%CVE-2023-22635MEDIUMA download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 allEPSS 0.1%CVE-2026-30603MEDIUMAn issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, aEPSS 0.1%CVE-2026-13433HIGHIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.1%CVE-2026-62654HIGHA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key EPSS 0.1%CVE-2025-61228HIGHAn issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanismEPSS 0.1%CVE-2025-65855MEDIUMThe OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentiaEPSS 0.1%CVE-2025-52937LOWVulnerability in PointCloudLibrary PCLEPSS 0.1%CVE-2026-84664MEDIUMJenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowinEPSS 0.1%CVE-2026-84666MEDIUMJenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration thEPSS 0.1%CVE-2026-12259MEDIUMImproper Input Validation in nltk/nltkEPSS 0.1%CVE-2024-39819MEDIUMZoom Workplace Apps and SDK for Windows - Improper Privilege ManagementEPSS 0.1%CVE-2025-53696CRITICALiSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmEPSS 0.1%CVE-2026-7006HIGHSublime Text 4192/3207 Local Privilege Escalation via Update Staging MechanismEPSS 0.1%CVE-2025-47904MEDIUMUnsigned upgrade packageEPSS 0.1%CVE-2024-42183LOWHCL BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerabilityEPSS 0.1%CVE-2026-76241HIGHstigmem Plugin Signature Enforcement Bypass via ConfigurationEPSS 0.1%CVE-2026-80047HIGHHugging Face Transformers library writes remote code to disk prior to consent checkEPSS 0.1%