Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-49558HIGHDell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerabilityEPSS 0.1%CVE-2024-20262MEDIUMA vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to EPSS 0.1%CVE-2026-15379MEDIUMArbitrary File Read as SYSTEM in Symantec ITMSEPSS 0.1%CVE-2024-5760HIGHThe Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shellEPSS 0.1%CVE-2023-40686MEDIUMIBM i privilege escalationEPSS 0.1%CVE-2026-82670MEDIUMIObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges managementEPSS 0.1%CVE-2025-10657HIGHDocker Desktop with ECI Fails to Enforce Socket Command RestrictionsEPSS 0.1%CVE-2026-58583HIGHFluxInk Color Management Driver local privilege escalationEPSS 0.1%CVE-2026-83211HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2026-83342HIGHVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). SupporteEPSS 0.1%CVE-2026-83147HIGHVulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported versionEPSS 0.1%CVE-2026-83118HIGHVulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected arEPSS 0.1%CVE-2024-31953MEDIUMAn issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used duEPSS 0.1%CVE-2026-30902HIGHZoom Clients for Windows - Improper Privilege ManagementEPSS 0.1%CVE-2026-83336HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported vEPSS 0.1%CVE-2026-83353HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.1%CVE-2026-0276LOWCortex XDR Broker VM: Privilege Escalation (PE) VulnerabilityEPSS 0.1%CVE-2026-83216HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2026-83214HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2021-3978HIGHImproper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpkiEPSS 0.1%