Fallos del tipo CWE-269

2492 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2023-4404CRITICALDonation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege EscalationEPSS 0.9%CVE-2018-25040MEDIUMuTorrent Web HTTP RPC Server privileges managementEPSS 0.9%CVE-2026-14526CRITICALAI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow RouteEPSS 0.9%CVE-2021-36307HIGHNetworking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low prEPSS 0.9%CVE-2021-36784HIGHPrivilege escalation for users with create/update permissions in Global RolesEPSS 0.9%CVE-2018-14808—Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on the affected productEPSS 0.9%CVE-2021-24158—Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege EscalationEPSS 0.9%CVE-2025-59693CRITICALThe Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) EPSS 0.9%CVE-2023-44250HIGHAn improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a ForEPSS 0.9%CVE-2023-27589MEDIUMMinio vulnerable to denial of access by an admin privileged user for root credentialEPSS 0.9%CVE-2022-26668HIGHASUS Control Center - Broken Access ControlEPSS 0.9%CVE-2022-42459HIGHWordPress Image Hover Effects Ultimate plugin <= 9.7.1 - Auth. WordPress Options Change vulnerabilityEPSS 0.9%CVE-2024-36439CRITICALSwissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash EPSS 0.9%CVE-2022-39202MEDIUMIRC mode parameter confusion in matrix-appservice-ircEPSS 0.9%CVE-2019-1162HIGHWindows ALPC Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-1762HIGHImproper Privilege Management in thorsten/phpmyfaqEPSS 0.9%CVE-2023-1326HIGHlocal privilege escalation in apport-cliEPSS 0.9%CVE-2021-31350HIGHJunos OS and Junos OS Evolved: Privilege escalation vulnerability in Juniper Extension Toolkit (JET)EPSS 0.9%CVE-2025-47955HIGHWindows Remote Access Connection Manager Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-8809CRITICALAdvanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' ParameterEPSS 0.9%