Fallos del tipo CWE-269

2508 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-81431HIGHRegistration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Unvalidated tgwcfb_idEPSS 0.5%CVE-2026-81810HIGHAll-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalation to Admin via Import Secret Key DisclosureEPSS 0.5%CVE-2026-92540HIGHImport and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_usersEPSS 0.5%CVE-2026-83117HIGHVulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected arEPSS 0.5%CVE-2026-83322HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.5%CVE-2026-83453HIGHVulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). SuppEPSS 0.5%CVE-2026-83328HIGHVulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions thatEPSS 0.5%CVE-2026-83268CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affecteEPSS 0.5%CVE-2026-83195HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.5%CVE-2026-92541HIGHImport and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend ImporterEPSS 0.5%CVE-2026-31834HIGHUmbraco Affected by Vertical Privilege Escalation via Missing Authorization ChecksEPSS 0.5%CVE-2026-80071HIGHUser Registration & Membership < 5.2.8 - Author+ Privilege Escalation to AdministratorEPSS 0.5%CVE-2026-83176HIGHVulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported veEPSS 0.5%CVE-2026-44787HIGHDiscourse: Signup-time primary_group_id assignment grants whisperer accessEPSS 0.5%CVE-2020-13776MEDIUMsystemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated byEPSS 0.5%CVE-2023-20598HIGH An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gainEPSS 0.5%CVE-2026-14960CRITICALCVE-2026-14960EPSS 0.5%CVE-2023-36628HIGHPrivilege Escalation in VASAEPSS 0.5%CVE-2026-56245HIGHSupabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning via record_build_time RPCEPSS 0.5%CVE-2024-1138HIGHTIBCO FTL Privilege EscalationEPSS 0.5%