Fallos del tipo CWE-269

2495 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-13439CRITICALEasy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST EndpointEPSS 0.7%CVE-2017-20038MEDIUMSICUNET Access Controller card_scan_decoder.php privileges managementEPSS 0.7%CVE-2022-42888CRITICALWordPress ARMember Plugin <= 5.5.1 is vulnerable to Privilege EscalationEPSS 0.7%CVE-2023-2240HIGHImproper Privilege Management in microweber/microweberEPSS 0.7%CVE-2026-75983HIGHEventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap FilterEPSS 0.7%CVE-2026-33334MEDIUMVikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegrationEPSS 0.7%CVE-2022-35243HIGHAuthenticated iControl REST in Appliance mode vulnerability CVE-2022-35243EPSS 0.7%CVE-2022-4173HIGHAvast and AVG Antivirus for Windows vulnerable to Privilege EscalationEPSS 0.7%CVE-2026-15017HIGHMDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' HandlersEPSS 0.7%CVE-2025-40548CRITICALSolarWinds Serv-U Broken Access Control - Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-6218HIGHMOVEit Transfer Group Admin Privilege EscalationEPSS 0.7%CVE-2023-23990HIGHWordPress Redirection for Contact Form 7 plugin <= 2.7.0 - Privilege Escalation vulnerabilityEPSS 0.7%CVE-2026-65595HIGHn8n before 2.29.8 and 2.30.1 Privilege Escalation via Token ExchangeEPSS 0.7%CVE-2022-31039MEDIUMImproper privilege management - Anyone can view room settings in GreenLightEPSS 0.7%CVE-2022-35291HIGHPrivilege escalation vulnerability in SAP SuccessFactors attachment API for Mobile Application(Android & iOS)EPSS 0.7%CVE-2026-62183CRITICALApache Syncope: User self-service privilege escalationEPSS 0.7%CVE-2026-32760CRITICALFile Browser Self Registration Grants Any User Admin Access When Default Permissions Include AdminEPSS 0.7%CVE-2026-19883HIGHWPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_actionEPSS 0.7%CVE-2026-15001HIGHbLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscriber+) Privilege Escalation via Unprotected AJAX API URL SettingsEPSS 0.7%CVE-2023-7090MEDIUMSudo: improper handling of ipa_hostname leads to privilege mismanagementEPSS 0.7%