Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-83317HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Installation). Supported versiEPSS 0.1%CVE-2026-83290HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.1%CVE-2026-83342HIGHVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). SupporteEPSS 0.1%CVE-2026-83420HIGHVulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported verEPSS 0.1%CVE-2026-30902HIGHZoom Clients for Windows - Improper Privilege ManagementEPSS 0.1%CVE-2026-83214HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2026-83147HIGHVulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported versionEPSS 0.1%CVE-2026-83293HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN). The supported version EPSS 0.1%CVE-2024-31953MEDIUMAn issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used duEPSS 0.1%CVE-2026-10610HIGHLocal privilege escalation in ESET security applications for macOSEPSS 0.1%CVE-2023-40377MEDIUMIBM i privilege escalationEPSS 0.1%CVE-2023-40378MEDIUMIBM i privilege escalationEPSS 0.1%CVE-2023-0192MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can leaEPSS 0.1%CVE-2023-7343HIGHBelden Industrial HiVision Arbitrary Code Execution via Malicious Project FileEPSS 0.1%CVE-2026-65354HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicioEPSS 0.1%CVE-2025-1037HIGHBy making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user level shell commands EPSS 0.1%CVE-2021-26734MEDIUMJunction Delete leading to elevation of privilegeEPSS 0.1%CVE-2026-86888LOWA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS TahEPSS 0.1%CVE-2022-1804MEDIUMAccountsservice incorrectly drops privilegesEPSS 0.1%CVE-2026-83190HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%