Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-73747LOWLocal Privilege Escalation Vulnerability in HPE Networking Fabric ComposerEPSS 0.1%CVE-2026-28548HIGHVulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service coEPSS 0.1%CVE-2026-7994HIGHInappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level pEPSS 0.1%CVE-2023-21397—In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of priEPSS 0.1%CVE-2024-31334MEDIUMIn DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This coEPSS 0.1%CVE-2026-11308MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malEPSS 0.1%CVE-2024-40662HIGHIn scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local esEPSS 0.1%CVE-2025-13917HIGHElevation of Privileges in Web Security Services (WSS) AgentEPSS 0.1%CVE-2021-25515MEDIUMAn improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.EPSS 0.1%CVE-2024-31311MEDIUMIn increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to loEPSS 0.1%CVE-2026-96812HIGHHost Root Sandbox Escape in gVisor via Character Device Passthrough and CUSEEPSS 0.1%CVE-2026-11229MEDIUMInappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation EPSS 0.1%CVE-2022-22263MEDIUMUnprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.EPSS 0.1%CVE-2026-0032HIGHIn multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local eEPSS 0.1%CVE-2026-79153HIGHSeclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that alEPSS 0.1%CVE-2023-20995—In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This couEPSS 0.1%CVE-2025-12683MEDIUMNULL DACL assigned to Named Pipe communicating with SYSTEM ServiceEPSS 0.1%CVE-2025-32345HIGHIn updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary userEPSS 0.1%CVE-2024-32906HIGHIn AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no adEPSS 0.1%CVE-2022-36861MEDIUMCustom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystEPSS 0.1%