Fallos del tipo CWE-269

2495 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2021-4200MEDIUMWrite access to the Catalog for any user when restricted-admin role is enabledEPSS 0.6%CVE-2020-26063MEDIUMCisco Integrated Management Controller Software Authorization Bypass VulnerabilityEPSS 0.6%CVE-2022-41604HIGHCheck Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissiEPSS 0.6%CVE-2026-31852CRITICALJellyfin Possible Organization/Secret Compromise from dangerous CI implementationEPSS 0.6%CVE-2025-11533CRITICALWP Freeio <= 1.2.21 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2024-9265CRITICALEcho RSS Feed Post Generator <= 5.4.6 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2020-36603MEDIUMThe HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calEPSS 0.6%CVE-2022-32829HIGHThis issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to eEPSS 0.6%CVE-2022-41948MEDIUMPrivilege Chaining with the user admin role in dhis2-coreEPSS 0.6%CVE-2021-34579HIGHPHOENIX CONTACT: FL MGUARD DM version 1.12.0 and 1.13.0 Improper Privilege ManagementEPSS 0.6%CVE-2025-29976HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2023-32197HIGHRancher's External RoleTemplates can lead to privilege escalationEPSS 0.6%CVE-2025-28399CRITICALAn issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address ControlEPSS 0.6%CVE-2023-28855MEDIUMFields GLPI plugin vulnerable to unauthorized write access to additional fieldsEPSS 0.6%CVE-2026-2563MEDIUMJingDong JD Cloud Box AX6600 jdcapp_rpc controlDevice get_status privileges managementEPSS 0.6%CVE-2026-50770CRITICALAn issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.EPSS 0.6%CVE-2026-50774CRITICALAn issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.EPSS 0.6%CVE-2023-29166—A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate prEPSS 0.6%CVE-2021-34487HIGHWindows Event Tracing Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-29667CRITICALSQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate priEPSS 0.6%