Fallos del tipo CWE-266

1161 resultados

Atribuição Incorreta de Privilégios

Quando um sistema concede permissões ou privilégios a um usuário, processo ou recurso de forma inadequada — maior que o necessário ou para a entidade errada. Isso permite que atacantes escalem privilégios ou acessem dados/funcionalidades que não deveriam ter.

Ejemplo

Um aplicativo web cria uma pasta temporária com permissões 777 (leitura, escrita e execução para todos), ou um serviço Windows roda como SYSTEM quando deveria rodar como usuário comum. Outro cenário: uma função administrativa fica acessível via URL sem validação, permitindo qualquer usuário logado executá-la.

Cómo mitigar

Aplique o princípio do menor privilégio: conceda apenas as permissões mínimas necessárias. Use ACLs restritivas, validação de roles/permissões em cada função sensível, execute serviços com contas de baixo privilégio, e mantenha auditoria de mudanças de permissões.

CVE-2024-27453HIGHIn Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of thEPSS 0.7%CVE-2024-12782MEDIUMFujifilm Business Innovation Apeos C3070/Apeos C5570/Apeos C6580 Web Interface index.html#hashHome improper authorizationEPSS 0.7%CVE-2020-26182MEDIUMDell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low priviEPSS 0.7%CVE-2025-62645CRITICALThe Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token witEPSS 0.7%CVE-2026-32922CRITICALOpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotateEPSS 0.7%CVE-2026-59093HIGHWeaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role AssignmentEPSS 0.7%CVE-2026-15271HIGHTOTOLINK EX200 Web boa.conf least privilege violationEPSS 0.7%CVE-2025-3536MEDIUMTutorials-Website Employee Management System delete-user.php improper authorizationEPSS 0.7%CVE-2025-10725CRITICALOpenshift-ai: overly permissive clusterrole allows authenticated users to escalate privileges to cluster adminEPSS 0.7%CVE-2025-2320MEDIUM274056675 springboot-openai-chatgpt User submit improper authorizationEPSS 0.7%CVE-2023-6815MEDIUMIncorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/120SFCPU all versionEPSS 0.7%CVE-2025-3537MEDIUMTutorials-Website Employee Management System update-user.php improper authorizationEPSS 0.7%CVE-2024-10978MEDIUMPostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user IDEPSS 0.7%CVE-2024-32444CRITICALWordPress RealHomes theme <= 4.3.6 - Privilege Escalation vulnerabilityEPSS 0.7%CVE-2025-13888CRITICALOpenshift-gitops-operator: openshift gitops: namespace admin cluster takeover via privileged jobsEPSS 0.7%CVE-2025-23970CRITICALWordPress Service Finder Booking plugin <= 6.1 - Privilege Escalation VulnerabilityEPSS 0.7%CVE-2023-50437HIGHAn issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and EPSS 0.7%CVE-2025-3236MEDIUMTenda FH1202 Web Management Interface VirSerDMZ access controlEPSS 0.7%CVE-2021-20208A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use KerberoEPSS 0.7%CVE-2024-12213CRITICALWP Job Board Pro < 1.2.85 - Unauthenticated Privilege Escalation via process_registerEPSS 0.7%