Fallos del tipo CWE-269

2508 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-9842HIGHBackstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role CapabilitiesEPSS 0.4%CVE-2021-46894—Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalatioEPSS 0.4%CVE-2025-21360HIGHMicrosoft AutoUpdate (MAU) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-8263MEDIUMAn improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use ofEPSS 0.4%CVE-2022-34706HIGHWindows Local Security Authority (LSA) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-45373HIGHDover Fueling Solutions ProGauge MAGLINK LX CONSOLE Improper Privilege ManagementEPSS 0.4%CVE-2024-32960HIGHWordPress Booking Ultra Pro plugin 1.1.12 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2024-10203HIGHAgent Arbitrary File DeletionEPSS 0.4%CVE-2026-93968MEDIUMaiyiyi121 SxDevOps UserSerializer serializers.py update privileges managementEPSS 0.4%CVE-2025-34251HIGHTesla Telematics Control Unit (TCU) < v2025.14 Authentication BypassEPSS 0.4%CVE-2023-29056MEDIUMA valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC mustEPSS 0.4%CVE-2025-55187CRITICALIn DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.EPSS 0.4%CVE-2024-51324LOWAn issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (BriEPSS 0.4%CVE-2025-2237CRITICALWP RealEstate <= 1.6.26 - Unauthenticated Privilege Escalation via 'process_register'EPSS 0.4%CVE-2024-27711HIGHAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up pEPSS 0.4%CVE-2026-74965HIGHPrivilege escalation in the Shell Integration componentEPSS 0.4%CVE-2025-44040HIGHAn issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication dEPSS 0.4%CVE-2022-29614—SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22EPSS 0.4%CVE-2026-74953HIGHPrivilege escalation in the Networking: Cookies componentEPSS 0.4%CVE-2024-39634HIGHWordPress PowerPack Pro for Elementor plugin <= 2.10.14 - Contributor+ Privilege Escalation vulnerabilityEPSS 0.4%