Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-33187CRITICALNVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areasEPSS 0.2%CVE-2023-41138HIGHThe AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user pEPSS 0.2%CVE-2026-87183HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2026-12313MEDIUMInformation disclosure, sandbox escape in the Security: Process Sandboxing componentEPSS 0.2%CVE-2026-49883CRITICALIn checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permissioEPSS 0.2%CVE-2026-46877MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affecEPSS 0.2%CVE-2024-23764MEDIUMCertain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server SecuriEPSS 0.2%CVE-2021-3439HIGHHP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate tEPSS 0.2%CVE-2023-35140MEDIUMThe improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated EPSS 0.2%CVE-2025-65621MEDIUMSnipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administratorEPSS 0.2%CVE-2023-40155MEDIUMUncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalEPSS 0.2%CVE-2023-5993HIGHPrivilege Escalation in SafeNet Authentication Client InstallerEPSS 0.2%CVE-2022-3990HIGHHPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customers who opted for autoEPSS 0.2%CVE-2024-9002HIGHCWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and avEPSS 0.2%CVE-2025-36631HIGHLocal Privilege EscalationEPSS 0.2%CVE-2025-37186HIGHLocal Privilege Escalation Vulnerability in HPE Aruba Networking Virtual Intranet Access (VIA) Client for LinuxEPSS 0.2%CVE-2024-4018HIGHPrivilege Escalation in U-Series ApplianceEPSS 0.2%CVE-2026-18759HIGHAn improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.EPSS 0.2%CVE-2024-52926MEDIUMDelinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.EPSS 0.2%CVE-2022-48227HIGHAn issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the instEPSS 0.2%