Fallos del tipo CWE-269

2492 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2017-20063MEDIUMElefant CMS File Upload drop privileges managementEPSS 0.9%CVE-2026-75977HIGHMang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication CookieEPSS 0.9%CVE-2022-45608—An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and EPSS 0.9%CVE-2023-37859HIGHPHOENIX CONTACT: Improper Privilege Management in WP 6xxx Web panelsEPSS 0.9%CVE-2022-48365HIGHAn issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.EPSS 0.9%CVE-2020-12519HIGHPhoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An attacker can use this vulnerability i.e. to open a reverse shell with root privileges.EPSS 0.9%CVE-2020-12528MEDIUMAn issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access valEPSS 0.9%CVE-2024-37726MEDIUMInsecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privilegesEPSS 0.9%CVE-2017-9940—A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-prEPSS 0.9%CVE-2023-3636HIGHWP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege EscalationEPSS 0.9%CVE-2022-3422CRITICALImproper Privilege Management in tooljet/tooljetEPSS 0.9%CVE-2023-34465CRITICALXWiki Platform's Mail.MailConfig can be edited by any user with edit rightsEPSS 0.9%CVE-2021-31937HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-44809—D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.EPSS 0.9%CVE-2025-22254MEDIUMAn Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6,EPSS 0.8%CVE-2017-20023MEDIUMSolare Solar-Log Network Config privileges managementEPSS 0.8%CVE-2024-33894HIGHInsecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing severEPSS 0.8%CVE-2023-4697HIGHImproper Privilege Management in usememos/memosEPSS 0.8%CVE-2022-38757HIGHCVE-2022-38757 ZENworksEPSS 0.8%CVE-2022-39203HIGHParsing issue in matrix-org/node-irc leading to room takeoversEPSS 0.8%