Fallos del tipo CWE-269

2497 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-23093HIGHThe Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authentEPSS 0.6%CVE-2025-12485HIGHImproper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonateEPSS 0.6%CVE-2022-41268HIGHIn some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200EPSS 0.6%CVE-2024-35430HIGHIn ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data froEPSS 0.6%CVE-2026-15414HIGHSubscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan MetaEPSS 0.6%CVE-2025-47713HIGHApache CloudStack: Domain Admin can reset Admin password in Root DomainEPSS 0.6%CVE-2025-47849HIGHApache CloudStack: Insecure access of user's API/Secret Keys in the same domainEPSS 0.6%CVE-2021-23265LOWImproper Privilege Management in Crafter StudioEPSS 0.6%CVE-2026-16149HIGHSecurity Hardener <= 2.4.4 - Authenticated (Subscriber+) Privilege Escalation via REST API '/wp/v2/users' permission_callback OverwriteEPSS 0.6%CVE-2026-7106HIGHHighland Software Custom Role Manager <= 1.0.0 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.6%CVE-2024-3325HIGHJasperReports Server Driver upload vulnerabilityEPSS 0.6%CVE-2026-5144HIGHBuddyPress Groupblog <= 1.9.3 - Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOREPSS 0.6%CVE-2026-6750HIGHPrivilege escalation in the Graphics: WebRender componentEPSS 0.6%CVE-2024-45041HIGHExternal Secrets Operator vulnerable to privilege escalationEPSS 0.6%CVE-2024-31502HIGHAn issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /adEPSS 0.6%CVE-2020-8290—Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack EPSS 0.6%CVE-2024-21622MEDIUMCraft CMS Privilege EscalationEPSS 0.6%CVE-2026-18322HIGHSmart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to AdministratorEPSS 0.6%CVE-2026-9018HIGHEasy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' ParameterEPSS 0.6%CVE-2026-14482HIGH多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'value' ParametersEPSS 0.6%