Fallos del tipo CWE-269

2493 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-22829LOWApache CloudStack: Unauthorised access to dedicated resources in Quota pluginEPSS 0.8%CVE-2023-0101HIGHA privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attEPSS 0.8%CVE-2022-4314MEDIUMImproper Privilege Management in ikus060/rdiffwebEPSS 0.8%CVE-2021-27661HIGHFacility ExplorerEPSS 0.8%CVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 0.8%KEVCVE-2017-20028MEDIUMHumHub privileges managementEPSS 0.8%CVE-2022-35771HIGHWindows Defender Credential Guard Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2023-25701CRITICALWordPress WatchTowerHQ plugin <= 3.6.16 - Privilege EscalationEPSS 0.8%CVE-2025-11561HIGHSssd: sssd default kerberos configuration allows privilege escalation on ad-joined linux systemsEPSS 0.8%CVE-2026-61781CRITICALpg_partman has privilege escalation through SQL injection in create_partition_time()EPSS 0.8%CVE-2021-27394—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (AllEPSS 0.8%CVE-2026-12415CRITICALInvoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' ParameterEPSS 0.8%CVE-2024-1442MEDIUMUser with permissions to create a data source can CRUD all data sourcesEPSS 0.8%CVE-2026-2631CRITICALDatalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege EscalationEPSS 0.8%CVE-2024-9636CRITICALPost Grid and Gutenberg Blocks 2.2.85 - 2.3.3 - Unauthenticated Privilege EscalationEPSS 0.8%CVE-2021-3919CRITICALA potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege aEPSS 0.8%CVE-2026-22708HIGHCursor has a Terminal Tool Allowlist Bypass via Environment VariablesEPSS 0.8%CVE-2022-39032HIGHSmart eVision - Improper Privilege ManagementEPSS 0.8%CVE-2023-32696HIGHExcessive permissions for ckan userEPSS 0.8%CVE-2024-20374MEDIUMA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower ManagemeEPSS 0.8%