Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-57760HIGHLangflow Vulnerable to Privilege Escalation via CLI Superuser CreationEPSS 0.5%CVE-2026-12793CRITICALJetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' ParameterEPSS 0.5%CVE-2023-4607HIGHAn authenticated XCC user can change permissions for any user through a crafted API command.EPSS 0.5%CVE-2020-13511MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specialEPSS 0.5%CVE-2020-13518MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c402084 functionality of NZXT CAM 4.8.0. A specially craftedEPSS 0.5%CVE-2020-13516MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406144 functionality of NZXT CAM 4.8.0. A specially craftedEPSS 0.5%CVE-2024-43403HIGHKanister has a potential risk which can be leveraged to make a cluster-level privilege escalationEPSS 0.5%CVE-2025-25962CRITICALAn issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition funcEPSS 0.5%CVE-2022-35921LOWUser preference to prevent private discussions not respected in fof/byobuEPSS 0.5%CVE-2026-94609HIGHauthentik: Privilege Escalation to Superuser via Group HierarchyEPSS 0.5%CVE-2025-46116HIGHAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.EPSS 0.5%CVE-2026-14956CRITICALBricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds ParameterEPSS 0.5%CVE-2026-9055CRITICALBooking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'EPSS 0.5%CVE-2026-37071CRITICALArbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authentEPSS 0.5%CVE-2026-84795CRITICALCraft CMS before 5.10.11 Authentication Bypass via Admin Flag InheritanceEPSS 0.5%CVE-2022-45451HIGHLocal privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber ProtectEPSS 0.5%CVE-2026-73470CRITICALApache Syncope: Delegating users can grant unowned RolesEPSS 0.5%CVE-2024-33549HIGHWordPress WZone plugin <= 14.0.10 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-82857CRITICALhulumi before v1.3.2 Privilege Escalation via IAM PolicyEPSS 0.5%CVE-2023-5978—Incorrect libcap_net limitation list manipulationEPSS 0.5%