Fallos del tipo CWE-264

299 resultados

Controle de acesso e privilégios inadequado

A aplicação não valida ou não implementa corretamente as permissões necessárias para acessar recursos sensíveis, permitindo que usuários realizem operações além do seu nível de privilégio autorizado. Isso pode expor dados confidenciais, modificar informações críticas ou comprometer a integridade do sistema.

Ejemplo

Um usuário comum consegue acessar diretamente uma rota administrativa (/admin/users) porque o backend não verifica se ele é administrador antes de executar a ação, apenas confiando que não tentaria; ou um processo de aplicação roda como root quando precisaria rodar como usuário não-privilegiado, ampliando o impacto de qualquer falha.

Cómo mitigar

Implemente validação de privilégios em todas as operações sensíveis (verificar permissões no servidor, nunca só no cliente), use princípio do menor privilégio (processos e contas com permissões mínimas necessárias), e mantenha matriz de controle de acesso (RBAC ou ABAC) consistente e auditada.

CVE-2020-7257HIGHPrivilege Escalation vulnerability through Symbolic links in ENSEPSS 0.3%CVE-2020-7259MEDIUMUnsigned executable vulnerability in ENS can be used to bypass intended self-protection rulesEPSS 0.3%CVE-2026-49310HIGHPermission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service EPSS 0.3%CVE-2024-22452HIGHDell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potEPSS 0.2%CVE-2020-7255LOWPrivilege Escalation vulnerability  in ENSEPSS 0.2%CVE-2021-28497MEDIUMIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell mEPSS 0.2%CVE-2022-23714A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which EPSS 0.2%CVE-2023-52955MEDIUMVulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause feEPSS 0.2%CVE-2019-19107MEDIUMABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Information ExposureEPSS 0.2%CVE-2026-6117MEDIUMAstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandboxEPSS 0.2%CVE-2024-54104MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2020-1630MEDIUMJunos OS: Privilege escalation vulnerability in dual REs, VC or HA cluster may allow unauthorized configuration change.EPSS 0.2%CVE-2020-11933HIGHlocal snapd exploit through cloud-initEPSS 0.2%CVE-2024-56440MEDIUMPermission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perfEPSS 0.2%CVE-2024-45442MEDIUMVulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability wEPSS 0.2%CVE-2018-6674MEDIUMPrivilege escalation vulnerability in McAfee VSE when McTray run with elevated privilegesEPSS 0.2%CVE-2024-54103MEDIUMVulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidEPSS 0.2%CVE-2020-7263MEDIUMENS configuration can be edited by attacker with local administrator permissionsEPSS 0.2%CVE-2024-20370MEDIUMA vulnerability in the Cisco FXOS CLI feature on specific hardware platforms for Cisco Adaptive Security Appliance (ASA) Software and Cisco EPSS 0.2%CVE-2023-52721MEDIUMThe WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confideEPSS 0.2%