Fallos del tipo CWE-250

373 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2026-24183HIGHNVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege manaEPSS 0.1%CVE-2026-21426MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges EPSS 0.1%CVE-2025-33003HIGHIBM InfoSphere Information Server is vulnerable to privilege escalationEPSS 0.1%CVE-2026-75092HIGHLeapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable pluginsEPSS 0.1%CVE-2026-21421MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges EPSS 0.1%CVE-2026-21424MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an execution with unnecessary privileges EPSS 0.1%CVE-2026-30512HIGHA local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI priEPSS 0.1%CVE-2026-0870HIGHGIGABYTE|MacroHub - Local Privilege EscalationEPSS 0.1%CVE-2025-36186HIGHIBM Db2 privilege escalationEPSS 0.1%CVE-2025-12690HIGHLocal Privilege Escalation in NGFW EngineEPSS 0.1%CVE-2026-40550MEDIUMPrivilege Escalation in mpGabinetEPSS 0.1%CVE-2026-71846MEDIUMInsights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch beyond least privilegeEPSS 0.1%CVE-2026-40638MEDIUMDell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability. A high privileged EPSS 0.1%CVE-2025-46696MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Execution with Unnecessary EPSS 0.1%CVE-2025-9055MEDIUMThe VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privilegesEPSS 0.1%CVE-2026-3315MEDIUMLocal Privilege Escalation Due to Writable Executable in Privileged Visionline Service PathEPSS 0.1%CVE-2026-14172HIGHRapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable InvocationEPSS 0.1%CVE-2026-79942LOWDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with UnEPSS 0.1%CVE-2025-34290HIGHVersa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege EscalationEPSS 0.1%CVE-2026-11626MEDIUMLocal Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal ToolEPSS 0.1%