Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-83150HIGHVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability EPSS 0.1%CVE-2026-60833HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. DifficEPSS 0.1%CVE-2026-60661HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. DiEPSS 0.1%CVE-2026-61061HIGHVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affEPSS 0.1%CVE-2020-9080HIGHThere is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specifiEPSS 0.1%CVE-2024-5907MEDIUMCortex XDR Agent: Local Privilege Escalation (PE) VulnerabilityEPSS 0.1%CVE-2025-14252HIGHAn Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, andEPSS 0.1%CVE-2026-22536HIGHPRIVILEGE ESCALATION VIA SUDO COMMANDEPSS 0.1%CVE-2025-5687HIGHLocal privilege escalation vulnerability in Mozilla VPN clients for macOS v2.27.0 and below.EPSS 0.1%CVE-2025-36640HIGHLocal Privilege EscalationEPSS 0.1%CVE-2025-5028MEDIUMArbitrary file deletion vulnerability in ESET product installersEPSS 0.1%CVE-2026-35154MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.1%CVE-2024-0674MEDIUMPrivilege escalation vulnerability in Lamassu Bitcoin ATM Douro machinesEPSS 0.1%CVE-2026-17877HIGHInappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level priEPSS 0.1%CVE-2026-14124HIGHInappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OSEPSS 0.1%CVE-2026-17864HIGHInappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilegEPSS 0.1%CVE-2025-26513HIGHThe installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited cEPSS 0.1%CVE-2025-10650LOWImproper SSH Key Handling in Internal Debug Builds May Grant Cluster-Level Access to Non-Administrative UsersEPSS 0.1%CVE-2024-57062MEDIUMAn issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the sessEPSS 0.1%CVE-2023-21113HIGHIn multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege withEPSS 0.1%