Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2019-15789HIGHMicrok8s Privilege Escalation VulnerabilityEPSS 0.5%CVE-2024-32511CRITICALWordPress Simple Registration for WooCommerce plugin <= 1.5.6 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-31290CRITICALWordPress Demo My WordPress plugin <= 1.0.9.1 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2024-33567CRITICALWordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.5.3 - Unauthenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-90523MEDIUMjaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges managementEPSS 0.5%CVE-2026-76670CRITICALAuthorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2026-16256CRITICALPouco Import Users <= 1.0.0 - Unauthenticated Privilege EscalationEPSS 0.5%CVE-2026-16298CRITICALFoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-85681CRITICALWP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option UpdateEPSS 0.5%CVE-2026-75860CRITICALJSON Options <= 0.0.4 - Unauthenticated Arbitrary Options UpdateEPSS 0.5%CVE-2026-76669CRITICALAuthorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2026-78362CRITICALSEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key AuthenticationEPSS 0.5%CVE-2026-18366CRITICALEvents Manager < 7.4.1 - Unauthenticated Privilege Escalation to AdministratorEPSS 0.5%CVE-2026-16722HIGHIBM i is Affected By An Unauthorized Privileges Vulnerability in SQL []EPSS 0.5%CVE-2026-9810CRITICALAI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuthEPSS 0.5%CVE-2026-17082HIGHIBM i is Affected By Multiple Vulnerabilities in the Debug ServerEPSS 0.5%CVE-2026-14545CRITICALTrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password ResetEPSS 0.5%CVE-2026-14719MEDIUMSourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges managementEPSS 0.5%CVE-2026-90856MEDIUMSourceCodester College Notes Gallery Management System Registration Flow signup.php privileges managementEPSS 0.5%CVE-2026-75837CRITICALGrav before 2.0.14 Privilege Escalation via Group Access FieldEPSS 0.5%