Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-4636HIGHLocal Privilege EscalationEPSS 0.2%CVE-2023-51435HIGH Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. EPSS 0.2%CVE-2023-20216MEDIUMA vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker EPSS 0.2%CVE-2024-0833HIGHPrivilege Elevation via Telerik Test StudioEPSS 0.2%CVE-2024-25961MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attaEPSS 0.2%CVE-2025-13176HIGHLocal privilege escalation in ESET Inspect Connector for WindowsEPSS 0.2%CVE-2024-37133MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacEPSS 0.2%CVE-2023-28122HIGHA local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with locEPSS 0.2%CVE-2026-70495HIGHSearch-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:mastersEPSS 0.2%CVE-2026-9489HIGHNitroSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2024-37126MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacEPSS 0.2%CVE-2024-44097CRITICALAccording to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validaEPSS 0.2%CVE-2024-32854MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attackEPSS 0.2%CVE-2025-36901HIGHWLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.EPSS 0.2%CVE-2022-45452HIGHLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 304EPSS 0.2%CVE-2026-46914HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. EasEPSS 0.2%CVE-2023-3699HIGHAn Improper Privilege Management vulnerability was found on the ADMEPSS 0.2%CVE-2026-83598HIGHNetdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI RepairEPSS 0.2%CVE-2025-0834HIGHWondershare Dr.Fone Privilege Scalation VulnerabilityEPSS 0.2%CVE-2023-50450HIGHAn issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated prEPSS 0.2%