Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2022-27659MEDIUMOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, an authenticated aEPSS 0.5%CVE-2026-2144HIGHMagic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File StorageEPSS 0.5%CVE-2026-86275MEDIUMSourceCodester Syllabus-Aligned Learning Management & Examination System auth.php register privileges managementEPSS 0.5%CVE-2026-39961MEDIUMAiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSourceEPSS 0.5%CVE-2024-37455HIGHWordPress Ultimate Addons for elementor plugin <= 1.36.31 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-73122HIGHMulticloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespacesEPSS 0.5%CVE-2026-74941HIGHPrivilege escalation in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2026-1728CRITICALPrivilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account TakeoverEPSS 0.5%CVE-2024-29150HIGHAn issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.0EPSS 0.5%CVE-2025-70888CRITICALAn issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c componEPSS 0.5%CVE-2024-33872CRITICALKeyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of EPSS 0.5%CVE-2026-92053HIGHPrivilege escalation in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2026-42844HIGHGrav: Low-privileged API users can create super-admin accounts via blueprint-uploadEPSS 0.5%CVE-2022-35762HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-46617HIGHFission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap readEPSS 0.5%CVE-2023-47683HIGHWordPress Social Login, Social Sharing by miniOrange plugin <= 7.6.6 - Authenticated Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-52808HIGHGogs: Write-level collaborators can mutate admin-only repository settings via APIEPSS 0.5%CVE-2022-48353CRITICALSome smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which resulEPSS 0.5%CVE-2023-46758—Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service EPSS 0.5%CVE-2023-51479HIGHWordPress Build App Online plugin <= 1.0.19 - Authenticated Privilege Escalation vulnerabilityEPSS 0.5%