Fallos del tipo CWE-269

2495 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2023-37866HIGHWordPress JetFormBuilder plugin <= 3.0.8 - Authenticated Privilege Escalation vulnerabilityEPSS 0.8%CVE-2025-27639HIGHVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015.EPSS 0.8%CVE-2024-1505HIGHAcademy LMS – eLearning and online course solution for WordPress <= 1.9.19 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.8%CVE-2023-41665HIGHWordPress GiveWP plugin <= 2.33.0 - GiveWP Manager+ Privilege Escalation vulnerabilityEPSS 0.8%CVE-2022-28169HIGHBrocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege weEPSS 0.8%CVE-2023-4239HIGHReal Estate Manager <= 7.2 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege EscalationEPSS 0.8%CVE-2023-0959MEDIUMBhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link senEPSS 0.7%CVE-2026-22238CRITICALAdministrator Account Creation Vulnerability in BLUVOYIXEPSS 0.7%CVE-2021-36316MEDIUMDell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability in AUI. A malicious EPSS 0.7%CVE-2024-48903HIGHAn improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affectEPSS 0.7%CVE-2022-37015CRITICALSymantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, whichEPSS 0.7%CVE-2026-14262HIGHSimple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' ParameterEPSS 0.7%CVE-2026-75166HIGHInsecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/EPSS 0.7%CVE-2023-37917CRITICALPrivilege Escalation in kubepiEPSS 0.7%CVE-2026-72830HIGHGrav API Plugin before 1.0.13 RCE via ConfigController scope bypassEPSS 0.7%CVE-2026-71625CRITICALAn issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php componentEPSS 0.7%CVE-2023-41324HIGHAccount takeover through API in GLPIEPSS 0.7%CVE-2026-17145CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.7%CVE-2023-41807CRITICALLinux Local Privilege Escalation Via GoTTY PageEPSS 0.7%CVE-2025-14736CRITICALFrontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form FieldEPSS 0.7%