Fallos del tipo CWE-269

2490 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-24286HIGHA vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.EPSS 19.1%CVE-2023-40289HIGHA command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevatEPSS 17.8%CVE-2023-2833HIGHReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege EscalationEPSS 17.5%CVE-2024-5009HIGHWhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation VulnerabilityEPSS 17.4%CVE-2025-47411HIGHApache StreamPipes: Leverage of User ID for Privilege EscalationEPSS 16.2%CVE-2023-20048CRITICALA vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacEPSS 15.8%CVE-2023-38944CRITICALAn issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access EPSS 15.5%CVE-2021-1388CRITICALCisco ACI Multi-Site Orchestrator Application Services Engine Deployment Authentication Bypass VulnerabilityEPSS 14.8%CVE-2024-12284HIGHAuthenticated privilege escalationEPSS 13.3%CVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 13.0%KEVCVE-2013-0643HIGHThe Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 anEPSS 10.5%KEVCVE-2017-7922—An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly rEPSS 9.6%CVE-2025-8489CRITICALKing Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege EscalationEPSS 9.3%CVE-2024-29976MEDIUM** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware vEPSS 9.0%CVE-2019-1388HIGHAn elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'WinEPSS 8.6%KEVCVE-2023-28434HIGHMinIO is vulnerable to privilege escalation on Linux/MacOSEPSS 7.9%KEVCVE-2026-62145HIGHLocal Privilege Escalation in Gaia PortalEPSS 7.6%CVE-2020-3950HIGHVMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior bEPSS 7.3%KEVCVE-2025-4601HIGHRH - Real Estate WordPress Theme <= 4.4.0 - Authenticated (Subscriber+) Privilege EscalationEPSS 7.0%CVE-2021-30355—Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilegeEPSS 6.9%