Fallos del tipo CWE-269

2492 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2023-43457—An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/adminEPSS 1.0%CVE-2018-25044MEDIUMuTorrent Guest Account privileges managementEPSS 1.0%CVE-2023-36765HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2016-15002HIGHMONyog Ultimate Cookie privileges managementEPSS 1.0%CVE-2022-27487HIGHA improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptorEPSS 1.0%CVE-2021-34766MEDIUMCisco Smart Software Manager Privilege Escalation VulnerabilityEPSS 1.0%CVE-2025-49758HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2026-7465HIGHSpectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block AttributesEPSS 1.0%CVE-2021-36207HIGHMetasys privilege managementEPSS 1.0%CVE-2022-31707HIGHvRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the ImpoEPSS 1.0%CVE-2026-76801HIGHFireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege EscalationEPSS 0.9%CVE-2022-32801HIGHThis issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to gain root privileges.EPSS 0.9%CVE-2021-36302CRITICALAll Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user EPSS 0.9%CVE-2026-84869CRITICALScreenConnect Client: Guest-to-Host File Execution via File-Transfer ActionsEPSS 0.9%KEVCVE-2021-25442—Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.EPSS 0.9%CVE-2023-6099HIGHShenzhen Youkate Industrial Facial Love Cloud Payment System Account SystemMng.ashx privileges managementEPSS 0.9%CVE-2022-29164HIGHPrivilege Escalation in argo-workflowsEPSS 0.9%CVE-2024-45173HIGHAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MEPSS 0.9%CVE-2020-12495CRITICALENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege managementEPSS 0.9%CVE-2024-24892HIGHUnauthorized RCE in migration-toolsEPSS 0.9%