Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-12217HIGHDVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges managementEPSS 0.1%CVE-2025-15576HIGHJail chroot escape via fd exchange with a different jailEPSS 0.1%CVE-2024-20021MEDIUMIn atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of EPSS 0.1%CVE-2024-0024HIGHIn multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input vaEPSS 0.1%CVE-2021-25365MEDIUMAn improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.EPSS 0.1%CVE-2025-9912MEDIUMA local privilege escalation vulnerability in Nokia SR LinuxEPSS 0.1%CVE-2026-54099HIGHWindows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:mastersEPSS 0.1%CVE-2024-39342MEDIUMEntrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.eEPSS 0.1%CVE-2025-57840LOWPrivilege Bypass in ADBEPSS 0.1%CVE-2025-52347HIGHAn issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 BuEPSS 0.1%CVE-2025-69875HIGHA vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore pEPSS 0.1%CVE-2026-63349HIGHAnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groupsEPSS 0.1%CVE-2025-15561HIGHLocal Privilege Escalation in NesterSoft WorkTimeEPSS 0.1%CVE-2026-12518HIGHLocal privilege escalation in the Logi Options+ updater service on WindowsEPSS 0.1%CVE-2026-19915HIGHHP Support Assistant - Local Escalation of PrivilegeEPSS 0.1%CVE-2026-0029HIGHIn __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2024-31325HIGHIn multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to localEPSS 0.1%CVE-2024-36500HIGHPrivilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentialitEPSS 0.1%CVE-2024-51521MEDIUMInput parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affectEPSS 0.1%CVE-2024-36499MEDIUMVulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect servicEPSS 0.1%