Fallos del tipo CWE-269

2497 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-3470MEDIUMRepository administrator can bypass organization's ruleset using deploy keysEPSS 0.6%CVE-2026-54168MEDIUMPipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolutionEPSS 0.6%CVE-2024-22157CRITICALWordPress SalesKing plugin <= 1.6.15 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.6%CVE-2026-36102HIGHAn issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privEPSS 0.6%CVE-2022-46410HIGHAn issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root byEPSS 0.6%CVE-2023-51425CRITICALWordPress Rencontre plugin <= 3.10.1 - Unauthenticated Account Takeover vulnerabilityEPSS 0.6%CVE-2021-37911HIGHThe management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any syEPSS 0.6%CVE-2026-22039CRITICALKyverno Cross-Namespace Privilege Escalation via Policy apiCallEPSS 0.6%CVE-2024-9192HIGHWP Video Robot <= 1.20.0 - Authenticated (Subscriber+) Privilege Escalation via User Meta UpdateEPSS 0.6%CVE-2024-29052HIGHWindows Storage Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-33509HIGHpyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script ConfigurationEPSS 0.6%CVE-2019-3786HIGHBBR could run arbitrary scripts on deployment VMsEPSS 0.6%CVE-2023-39734—The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token anEPSS 0.6%CVE-2022-24072—The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store weEPSS 0.6%CVE-2026-42609HIGHGrav: Administrative Account Disruption and Privilege De-escalation via User Overwrite LogicEPSS 0.6%CVE-2026-75971HIGHShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' NodesEPSS 0.6%CVE-2026-13228HIGHLatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' ParameterEPSS 0.6%CVE-2026-16635HIGHPronamic Pay <= 10.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms 'Update user role' FieldEPSS 0.6%CVE-2023-39740—The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadEPSS 0.6%CVE-2023-39732—The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broaEPSS 0.6%