Fallos del tipo CWE-250

370 resultados

Execução com privilégios desnecessários

É quando um programa ou processo roda com mais permissões do que precisa para executar suas funções normais. Se esse programa for comprometido, o atacante herda todos esses privilégios extras, ampliando drasticamente o dano possível. É o oposto do princípio do menor privilégio.

Ejemplo

Um daemon web que deveria apenas servir arquivos estáticos roda como root ao invés de um usuário específico sem privilégios. Se a aplicação web tiver uma vulnerabilidade de RCE, o invasor já está dentro com acesso total ao sistema, podendo alterar qualquer arquivo ou iniciar ataques laterais.

Cómo mitigar

Implemente o princípio do menor privilégio: crie contas de serviço dedicadas com apenas as permissões necessárias, use drop privileges em runtime quando possível, configure containers e VMs com usuários não-root, e revise regularmente quais recursos cada aplicação realmente precisa acessar.

CVE-2026-18949HIGHOdh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resourcesEPSS 0.4%CVE-2026-89259CRITICALHugo before v0.165.0 Insufficient Permission Restriction via TailwindCSSEPSS 0.4%CVE-2025-13506HIGHImproper Authorization in Nebim Neyir's Nebim V3 ERPEPSS 0.4%CVE-2025-1137HIGHIBM Storage Scale command injectionEPSS 0.4%CVE-2025-67510CRITICALMySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)EPSS 0.4%CVE-2025-62503MEDIUMApache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)EPSS 0.4%CVE-2025-59481HIGHBIG-IP iControl REST and tmsh vulnerabilityEPSS 0.4%CVE-2025-61958HIGHBIG-IP TMSH vulnerabilityEPSS 0.4%CVE-2022-41950MEDIUMPrivilege Escalation Vulnerability by wrong chmod paramEPSS 0.4%CVE-2021-3101HIGHHotdog Container EscapeEPSS 0.4%CVE-2022-0071HIGHHotdog Container EscapeEPSS 0.4%CVE-2026-76018HIGHPrivilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentiallEPSS 0.4%CVE-2023-50015HIGHAn issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect acEPSS 0.4%CVE-2025-33109HIGHIBM i privilege escalationEPSS 0.4%CVE-2021-0223HIGHJunos OS: telnetd.real Local Privilege Escalation vulnerabilities in SUID binariesEPSS 0.4%CVE-2018-25078HIGHman-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is exeEPSS 0.4%CVE-2022-0070HIGHLog4j hot patch package privilege escalationEPSS 0.4%CVE-2021-1118HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to execute privileged oEPSS 0.4%CVE-2024-47903MEDIUMA vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All veEPSS 0.4%CVE-2026-72654MEDIUMExecution with Unnecessary Privileges in Kibana Leading to Information DisclosureEPSS 0.4%