Fallos del tipo CWE-269

2500 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-34393HIGHWeblate: Privilege escalation in the user API endpointEPSS 0.5%CVE-2024-12398HIGHAn improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) anEPSS 0.5%CVE-2024-38770CRITICALWordPress Backup and Staging by WP Time Capsule plugin <= 1.22.20 - Authentication Bypass and Privilege Escalation VulnerabilityEPSS 0.5%CVE-2023-43845CRITICALAten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials EPSS 0.5%CVE-2022-41339HIGHIn Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.EPSS 0.5%CVE-2020-13512HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2020-13513HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2020-13514HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A speciallyEPSS 0.5%CVE-2020-13515HIGHA privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/EPSS 0.5%CVE-2023-50726MEDIUMUsers with `create` but not `override` privileges can perform local sync in argo-cdEPSS 0.5%CVE-2024-25847CRITICALSQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6EPSS 0.5%CVE-2020-13517MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0. A specially craftedEPSS 0.5%CVE-2024-4545HIGHEDB Postgres Advanced Server (EPAS) authenticated file read permissions bypass using edbldrEPSS 0.5%CVE-2025-4315HIGHCubeWP – All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.5%CVE-2022-4264MEDIUMIncorrect privilege assignment in M-Files Web ServerEPSS 0.5%CVE-2026-26722CRITICALAn issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN componEPSS 0.5%CVE-2022-4270LOWIncorrect privilege assignment in M-Files Web ServerEPSS 0.5%CVE-2026-5118CRITICALDivi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'EPSS 0.5%CVE-2026-15982CRITICALAimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'EPSS 0.5%CVE-2024-44893CRITICALAn issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET requeEPSS 0.5%