Fallos del tipo CWE-267

68 resultados

Privilégio Definido com Ações Inseguras

Quando um sistema concede privilégios elevados a um usuário ou processo, mas não restringe adequadamente quais ações podem ser executadas com esses privilégios. O atacante consegue executar operações perigosas (leitura/escrita de arquivos críticos, modificação de configurações do sistema, etc.) aproveitando o acesso amplo e mal definido.

Ejemplo

Um aplicativo web executa tarefas administrativas em nome de usuários. Se a lógica de autorização apenas verifica 'é admin?' mas não valida 'um admin pode deletar usuários de produção a partir dessa rota?', um atacante autenticado como admin consegue executar ações não intencionais e destrutivas.

Cómo mitigar

Implemente controle de acesso baseado em roles específicas e granulares (RBAC ou ABAC), validando não apenas quem é o usuário, mas que ações concretas aquela função está autorizada a fazer em cada contexto. Revise regularmente as permissões atribuídas e registre (log) todas as operações privilegiadas.

CVE-2026-2460HIGHA vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by usingEPSS 0.3%CVE-2017-2616MEDIUMA race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attackEPSS 0.3%CVE-2026-27314HIGHApache Cassandra: Privilege escalation via ADD IDENTITY authorization bypassEPSS 0.3%CVE-2025-36255HIGHDS8900F and DS8A00 Privilege EscalationEPSS 0.3%CVE-2024-7571HIGHIncorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.EPSS 0.3%CVE-2024-39866HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to uploEPSS 0.2%CVE-2026-0945MEDIUMRole Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002EPSS 0.2%CVE-2024-47906HIGHExcessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before versiEPSS 0.2%CVE-2024-8539HIGHImproper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configEPSS 0.2%CVE-2024-9842HIGHIncorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary foldersEPSS 0.2%CVE-2025-62589HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-62588HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2026-81161LOWContent Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107EPSS 0.2%CVE-2025-62641HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-62590HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2025-2903HIGHPrivilege Chaining in DelphixEPSS 0.2%CVE-2025-62587HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2023-44218HIGH A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system EPSS 0.2%CVE-2025-62591MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.2%CVE-2024-5623MEDIUMUntrusted search path vulnerability in B&R APROLEPSS 0.2%