Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2023-30988HIGHIBM i privilege escalationEPSS 0.2%CVE-2023-30989HIGHIBM i privilege escalationEPSS 0.2%CVE-2026-15380MEDIUMLocal privilege escalation in Symantec ITMSEPSS 0.2%CVE-2026-2914HIGHCyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elEPSS 0.2%CVE-2026-73974MEDIUMlinuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)EPSS 0.2%CVE-2022-41700MEDIUMInsecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticatEPSS 0.2%CVE-2026-76259HIGHImproper Privilege Management on the Management Port in Splunk Enterprise for WindowsEPSS 0.2%CVE-2023-41784MEDIUMPermissions and Access Control Vulnerability in ZTE Red Magic 8 ProEPSS 0.2%CVE-2025-64507HIGHIncus vulnerable to local privilege escalation through custom storage volumesEPSS 0.2%CVE-2026-16874HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2017-6894HIGHA vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that aEPSS 0.2%CVE-2025-13918MEDIUMElevation of Privileges in Symantec Endpoint Protection Windows ClientEPSS 0.2%CVE-2026-28919HIGHA consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS TahoEPSS 0.2%CVE-2022-25631HIGHSymantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a tEPSS 0.2%CVE-2026-29111MEDIUMsystemd: Local unprivileged user can trigger an assertEPSS 0.2%CVE-2022-46334HIGHProofpoint Enterprise Protection Local Privilege EscalationEPSS 0.2%CVE-2026-39118HIGHAn issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke EPSS 0.2%CVE-2026-53565HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2026-8069HIGHPredatorSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2023-25011HIGHPC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the registry as administrEPSS 0.2%