Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2022-36861MEDIUMCustom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystEPSS 0.1%CVE-2023-21068—In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to localEPSS 0.1%CVE-2023-20680MEDIUMIn adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2023-21374—In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of pEPSS 0.1%CVE-2023-35667—In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a lEPSS 0.1%CVE-2026-58874HIGHIn multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead EPSS 0.1%CVE-2025-66324HIGHInput verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affeEPSS 0.1%CVE-2025-48613HIGHIn VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the EPSS 0.1%CVE-2026-0009HIGHIn multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege witEPSS 0.1%CVE-2023-21376MEDIUMIn Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosurEPSS 0.1%CVE-2023-20655HIGHIn mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code execution with no additEPSS 0.1%CVE-2023-40106HIGHIn sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. ThisEPSS 0.1%CVE-2025-6177HIGHChromeOS MiniOS Root Code Execution Bypass While Dev Mode BlockedEPSS 0.1%CVE-2024-22008HIGHIn config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatEPSS 0.1%CVE-2026-0023HIGHIn createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permisEPSS 0.1%CVE-2025-26462HIGHIn AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to EPSS 0.1%CVE-2025-26435HIGHIn updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary userEPSS 0.1%CVE-2026-24510MEDIUMDell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerability. A low privileged EPSS 0.1%CVE-2024-25987MEDIUMIn pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation EPSS 0.1%CVE-2026-28586LOWIn multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to loEPSS 0.1%