Fallos del tipo CWE-269

2498 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-12981CRITICALListee <= 1.1.6 - Unauthenticated Privilege EscalationEPSS 0.6%CVE-2020-13519HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/EPSS 0.6%CVE-2026-7329CRITICALPrivilege escalation in Progress MarkLogic Server REST query interfacesEPSS 0.6%CVE-2024-33552CRITICALWordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerabilityEPSS 0.6%CVE-2026-66015HIGHJFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.EPSS 0.6%CVE-2026-92957CRITICALvm2 before 3.11.7 Authentication Bypass via node: PrefixEPSS 0.6%CVE-2022-3641HIGHElevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated useEPSS 0.6%CVE-2023-39733—The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mEPSS 0.6%CVE-2026-73293HIGHSemaphore UI: Manager-to-owner privilege escalation via custom-role slug collisionEPSS 0.6%CVE-2024-2433MEDIUMPAN-OS: Improper Privilege Management Vulnerability in Panorama Software Leads to Availability LossEPSS 0.6%CVE-2026-2777CRITICALPrivilege escalation in the Messaging System componentEPSS 0.6%CVE-2023-46145HIGHWordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerabilityEPSS 0.6%CVE-2024-31498HIGHYubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windoEPSS 0.6%CVE-2026-26416HIGHAn authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate privilegeEPSS 0.6%CVE-2024-7493CRITICALWPCOM Member <= 1.5.2.1 - Unauthenticated Privilege Escalation via User MetaEPSS 0.6%CVE-2025-57118CRITICALAn issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.phpEPSS 0.6%CVE-2024-27710CRITICALAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentiEPSS 0.6%CVE-2026-55485HIGHPiccolo Admin: Privilege escalation - admin to superuser via session-token disclosure in GET /api/tables/sessions/.EPSS 0.6%CVE-2026-15103HIGHWPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path ParameterEPSS 0.6%CVE-2026-6741HIGHLatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' AbilityEPSS 0.6%