Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-72886CRITICALDokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)EPSS 0.5%CVE-2026-50545CRITICALFission Environment CRD PodSpec Injection Leading to Node Escape and Cluster TakeoverEPSS 0.5%CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.5%CVE-2026-61463HIGHShiori Authenticated Privilege Escalation via PATCH /api/v1/auth/accountEPSS 0.5%CVE-2021-35309—An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.EPSS 0.5%CVE-2026-8787HIGHFirebase Support & Chat Management <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Privilege EscalationEPSS 0.5%CVE-2026-73284HIGHRustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service AccountsEPSS 0.5%CVE-2026-4314HIGHThe Ultimate WordPress Toolkit – WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privilege Escalation via Menu Editor ModuleEPSS 0.5%CVE-2026-15312HIGHPropovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndpv_manager+) Privilege Escalation via 'role' ParameterEPSS 0.5%CVE-2026-14279HIGHWholesale Market <= 2.2.2 - Authenticated (Subscriber+) Privilege Escalation via 'role_required' ParameterEPSS 0.5%CVE-2021-38638HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2024-9518CRITICALUserPlus <= 2.0 - Unauthenticated Privilege EscalationEPSS 0.5%CVE-2024-34146MEDIUMJenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, aEPSS 0.5%CVE-2024-25343CRITICALTenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.EPSS 0.5%CVE-2025-0180CRITICALWP Foodbakery <= 4.7 - Unauthenticated Privilege Escalation in foodbakery_registration_validationEPSS 0.5%CVE-2023-41808HIGHArbitrary File Read As Root Via GoTTY PageEPSS 0.5%CVE-2023-33327HIGHWordPress Leyka plugin <= 3.30.2 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-26369HIGHJUNG eNet SMART HOME server 2.2.1/2.3.1 Privilege Escalation via setUserGroupEPSS 0.5%CVE-2023-36496HIGHDelegated Admin Virtual Attribute Provider Privilege EscalationEPSS 0.5%CVE-2023-50921CRITICALAn issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privEPSS 0.5%