Fallos del tipo CWE-269

2502 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-0353HIGHLocal privilege escalation in Windows productsEPSS 0.6%CVE-2026-23663HIGHMicrosoft Global Secure Access (GSA) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-47132CRITICALAn issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.EPSS 0.6%CVE-2026-76713HIGHAuthenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.6%CVE-2026-12981HIGHCAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password ResetEPSS 0.6%CVE-2019-25068MEDIUMAxios Italia Axios RE Connection REDefault.aspx privileges managementEPSS 0.6%CVE-2024-36077HIGHQlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attackEPSS 0.6%CVE-2024-25842HIGHAn issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop EPSS 0.5%CVE-2026-16337CRITICALImproper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms EPSS 0.5%CVE-2025-21287HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2024-57778HIGHAn issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from stEPSS 0.5%CVE-2026-2931HIGHAmelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password ChangeEPSS 0.5%CVE-2023-41309—Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availabilitEPSS 0.5%CVE-2026-60372CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60366CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60367CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2025-29033HIGHAn issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parEPSS 0.5%CVE-2026-27899HIGHWireGuard Portal Vulnerable to Privilege Escalation to Admin via User Self-UpdateEPSS 0.5%CVE-2023-50890HIGHWordPress Ultimate Addons for Elementor plugin <= 1.36.20 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2023-51398HIGHWordPress Ultimate Addons for Beaver Builder Premium plugin <= 1.35.14 - Privilege Escalation vulnerabilityEPSS 0.5%