Fallos del tipo CWE-267

68 resultados

Privilégio Definido com Ações Inseguras

Quando um sistema concede privilégios elevados a um usuário ou processo, mas não restringe adequadamente quais ações podem ser executadas com esses privilégios. O atacante consegue executar operações perigosas (leitura/escrita de arquivos críticos, modificação de configurações do sistema, etc.) aproveitando o acesso amplo e mal definido.

Ejemplo

Um aplicativo web executa tarefas administrativas em nome de usuários. Se a lógica de autorização apenas verifica 'é admin?' mas não valida 'um admin pode deletar usuários de produção a partir dessa rota?', um atacante autenticado como admin consegue executar ações não intencionais e destrutivas.

Cómo mitigar

Implemente controle de acesso baseado em roles específicas e granulares (RBAC ou ABAC), validando não apenas quem é o usuário, mas que ações concretas aquela função está autorizada a fazer em cada contexto. Revise regularmente as permissões atribuídas e registre (log) todas as operações privilegiadas.

CVE-2024-8631MEDIUMPrivilege Defined With Unsafe Actions in GitLabEPSS 0.5%CVE-2025-26467HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)EPSS 0.5%CVE-2022-38124MEDIUMUnwanted debug toolEPSS 0.5%CVE-2021-44476MEDIUMA sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read localEPSS 0.5%CVE-2023-43746HIGHBIG-IP Appliance mode external monitor vulnerabilityEPSS 0.4%CVE-2023-27895MEDIUMInformation Disclosure vulnerability in SAP Authenticator for AndroidEPSS 0.4%CVE-2025-14349HIGHBusiness Logic Error in Universal Software's FlexCity/KioskEPSS 0.4%CVE-2025-7691MEDIUMPrivilege Defined With Unsafe Actions in GitLabEPSS 0.4%CVE-2026-10090CRITICALMulticluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscriptionEPSS 0.4%CVE-2026-29646CRITICALIn OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrEPSS 0.4%CVE-2025-7030MEDIUMTwo-factor Authentication (TFA) - Less critical - Access bypass - SA-CONTRIB-2025-085EPSS 0.4%CVE-2025-61754MEDIUMVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.3%CVE-2026-2459HIGHA vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the roleEPSS 0.3%CVE-2019-14865MEDIUMA flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example byEPSS 0.3%CVE-2026-6816MEDIUMTFA Basic Plugins - Access BypassEPSS 0.3%CVE-2025-62289MEDIUMVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is afEPSS 0.3%CVE-2025-62288MEDIUMVulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Logger). SEPSS 0.3%CVE-2026-23526HIGHCVAT vulnerable to privilege escalation of users with staff statusEPSS 0.3%CVE-2025-62480LOWVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that EPSS 0.3%CVE-2025-62479LOWVulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is EPSS 0.3%