Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-15982CRITICALAimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'EPSS 0.5%CVE-2026-5118CRITICALDivi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'EPSS 0.5%CVE-2022-4270LOWIncorrect privilege assignment in M-Files Web ServerEPSS 0.5%CVE-2020-35517—A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest usEPSS 0.5%CVE-2026-74985CRITICALPrivilege escalation in the Enterprise Policies componentEPSS 0.5%CVE-2023-47782HIGHWordPress Thrive Theme Builder theme < 3.24.0 - Authenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2022-25311HIGHA vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All EPSS 0.5%CVE-2026-27198HIGHFormwork Improperly Manages Privileges During User CreationEPSS 0.5%CVE-2026-47409HIGHpraisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}EPSS 0.5%CVE-2026-47412HIGHpraisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}EPSS 0.5%CVE-2024-7291HIGHJetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege EscalationEPSS 0.5%CVE-2026-76350HIGHImproper Privilege Management through PDF Attachments for Email Alert Actions in Splunk EnterpriseEPSS 0.5%CVE-2026-16904HIGHIBM i is Affected By improper privilege management in Navigator for iEPSS 0.5%CVE-2026-86553HIGHA password reset vulnerability in ZTE SmartLife APPEPSS 0.5%CVE-2023-33972HIGHPrivilege escalation from having CREATE access on a keyspace in ScylladbEPSS 0.5%CVE-2023-48319MEDIUMWordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-18713HIGHIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.5%CVE-2026-73305HIGHBudibase: Privilege escalation via public role assignment API missing app-level authorizationEPSS 0.5%CVE-2021-38638HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-18950HIGHOdh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref in rolebinding creationEPSS 0.5%