Fallos del tipo CWE-269

2495 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-45395HIGHOpen WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code ExecutionEPSS 0.7%CVE-2026-15426HIGHAcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template UpdateEPSS 0.7%CVE-2026-92619HIGHBooking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' ParameterEPSS 0.7%CVE-2025-0505CRITICALOn Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system stateEPSS 0.7%CVE-2023-41715HIGHSonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privilegEPSS 0.7%CVE-2026-24072HIGHApache HTTP Server: mod_rewrite elevation of privileges via ap_exprEPSS 0.7%CVE-2024-33308CRITICALAn issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the EmeEPSS 0.7%CVE-2025-2798CRITICALWoffice <= 5.4.21 - Authentication Bypass via Registration RoleEPSS 0.7%CVE-2022-43749MEDIUMImproper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authEPSS 0.6%CVE-2024-27181HIGHApache Linkis Basic management services: Privilege Escalation Attack vulnerabilityEPSS 0.6%CVE-2023-51546HIGHWordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerabilityEPSS 0.6%CVE-2026-85154CRITICALWWBN AVideo Authentication Bypass via Non-Expiring video_id_hashEPSS 0.6%CVE-2023-28339HIGHOpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTEEPSS 0.6%CVE-2024-8853CRITICALWebo-facto <= 1.40 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2024-0439HIGHUser can manually send request at manager permission to modify system configurationsEPSS 0.6%CVE-2023-0524HIGHAs part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a maliciouEPSS 0.6%CVE-2023-27094HIGHAn issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the tenant Management moEPSS 0.6%CVE-2026-75927HIGHPublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability GrantEPSS 0.6%CVE-2026-39386HIGHNeko has Self-service Privilege Escalation for Authenticated UsersEPSS 0.6%CVE-2023-46647HIGHImproper Privilege Management in GitHub Enterprise Server management console leads to privilege escalation EPSS 0.6%