Fallos del tipo CWE-269

2508 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-72829HIGHGrav before 1.0.13 API Key Scope Bypass via UsersControllerEPSS 0.5%CVE-2026-72833HIGHGrav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API KeysEPSS 0.5%CVE-2024-28905HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-1606LOWIncorrect privilege assignment in M-Files ServerEPSS 0.5%CVE-2022-35763HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-35764HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2022-35765HIGHStorage Spaces Direct Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-60369CRITICALVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-76687HIGHAuthenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2026-60439HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-61246HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-60373HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2023-22645HIGHkubewarden: Excessive permissions for kubewarden-controller-manager-cluster-roleEPSS 0.5%CVE-2024-29975MEDIUM** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versiEPSS 0.5%CVE-2026-17276CRITICALIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.5%CVE-2023-28436MEDIUMNon-interactive Tailscale SSH sessions on FreeBSD may use the effective group ID of the tailscaled processEPSS 0.5%CVE-2026-9193CRITICALPrivilege escalation in Progress MarkLogic Server Hadoop integrationEPSS 0.5%CVE-2025-54594CRITICALreact-native-bottom-tabs: Arbitrary code execution in GitHub Actions canary workflow leads to secret exfiltrationEPSS 0.5%CVE-2026-8709CRITICALPrivilege escalation in Progress MarkLogic Server REST document patch operationEPSS 0.5%CVE-2026-35595HIGHVikunja Affected by Privilege Escalation via Project ReparentingEPSS 0.5%