Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2022-48227HIGHAn issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the instEPSS 0.2%CVE-2023-5671—HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software updates to mitigate EPSS 0.2%CVE-2025-62625MEDIUMImproper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentiaEPSS 0.2%CVE-2022-45853MEDIUMThe privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHIEPSS 0.2%CVE-2026-30892NONECrun incorrectly parses `crun exec` option `-u`, leading to privilege escalationEPSS 0.2%CVE-2023-5739HIGHCertain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.EPSS 0.2%CVE-2023-32487HIGH Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentiallyEPSS 0.2%CVE-2023-32490MEDIUM Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentiallyEPSS 0.2%CVE-2026-6423HIGHLocal privilege escalation via unauthenticated ALPC in ESET Inspect ConnectorEPSS 0.2%CVE-2024-21059HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. DifficulEPSS 0.2%CVE-2026-45176HIGHIdira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation ManipulationEPSS 0.2%CVE-2023-31432HIGHPrivilege issues in multiple commandsEPSS 0.2%CVE-2025-54595HIGHPearcleaner's unauthenticated access to privileged XPC helper allows root command executionEPSS 0.2%CVE-2023-21896HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. DEPSS 0.2%CVE-2023-51386HIGHSandbox Accounts for Events vulnerable to privilege escalation to read running events dataEPSS 0.2%CVE-2026-73974MEDIUMlinuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)EPSS 0.2%CVE-2026-15380MEDIUMLocal privilege escalation in Symantec ITMSEPSS 0.2%CVE-2022-37019MEDIUMHP PC BIOS May 2024 Security Updates for Potential Stack Buffer OverflowsEPSS 0.2%CVE-2023-30988HIGHIBM i privilege escalationEPSS 0.2%CVE-2023-45883—A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers EPSS 0.2%