Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-6254CRITICALDoctreat Core <= 1.6.8 - Unauthenticated Privilege EscalationEPSS 0.5%CVE-2024-22774HIGHAn issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exEPSS 0.5%CVE-2025-64338MEDIUMClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection NameEPSS 0.5%CVE-2024-28904HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-46716CRITICALNezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cronEPSS 0.5%CVE-2026-72828HIGHGrav before 1.0.13 API Key Scope Bypass via InvitationsControllerEPSS 0.5%CVE-2026-68752HIGHProject Resource Managers may escalate privileges in JFrog ArtifactoryEPSS 0.5%CVE-2023-30617MEDIUMLeverage the kruise-daemon pod to list all secrets in the entire clusterEPSS 0.5%CVE-2020-13509MEDIUMAn information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specialEPSS 0.5%CVE-2026-48826HIGHHomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Tenant Header SwitchingEPSS 0.5%CVE-2024-48730MEDIUMThe default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions on the authenticatiEPSS 0.5%CVE-2026-54415HIGHBroken Access Control in Azuriom CMS Server Routes Allows Account TakeoverEPSS 0.5%CVE-2026-61107HIGHVulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.5%CVE-2026-87244HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-46867HIGHVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). SupEPSS 0.5%CVE-2026-61006HIGHVulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations). Supported EPSS 0.5%CVE-2026-60900HIGHVulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported verEPSS 0.5%CVE-2026-61336HIGHVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported verEPSS 0.5%CVE-2026-60340HIGHVulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions tEPSS 0.5%CVE-2026-62548HIGHVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.5%