Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-38765HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysEPSS 0.1%CVE-2026-83193HIGHVulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences). Supported versions that are affecEPSS 0.1%CVE-2026-29923HIGHThe pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL requeEPSS 0.1%CVE-2026-60162MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2026-86884MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, EPSS 0.1%CVE-2024-39574MEDIUMDell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local accessEPSS 0.1%CVE-2026-16743MEDIUMAccountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed usersEPSS 0.1%CVE-2026-83190HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.1%CVE-2026-29122HIGH`/bin/date` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPEEPSS 0.1%CVE-2024-42050HIGHThe MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A locEPSS 0.1%CVE-2026-80166HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper PrivilegEPSS 0.1%CVE-2026-38766HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 functionEPSS 0.1%CVE-2025-67905HIGHMalwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target locationEPSS 0.1%CVE-2026-83597HIGHNetdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair ExecutionEPSS 0.1%CVE-2026-20044MEDIUMCisco Secure Firewall Management Center Command Injection VulnerabilityEPSS 0.1%CVE-2026-80178MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper PrivilegEPSS 0.1%CVE-2025-1121MEDIUMPrivilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physicEPSS 0.1%CVE-2023-47201MEDIUMA plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privilEPSS 0.1%CVE-2017-13165MEDIUMAn elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android ID A-31269937.EPSS 0.1%CVE-2026-16703HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%