Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-37952HIGHWordPress BookYourTravel theme <= 8.18.17 - Subscriber+ Privilege Escalation vulnerabilityEPSS 0.4%CVE-2024-37484HIGHWordPress Zephyr Project Manager plugin <= 3.3.97 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-31286MEDIUMAn HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. EPSS 0.4%CVE-2026-6419HIGHWishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secret Key Disclosure and Privilege Escalation via 'wlm3_get_screen' AJAX actionEPSS 0.4%CVE-2026-75843CRITICALArcadeDB before 26.8.1 Privilege Escalation via gRPC TransactionEPSS 0.4%CVE-2026-13741HIGHDigits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' ParameterEPSS 0.4%CVE-2025-0177CRITICALJavo Core <= 3.0.0.080 - Unauthenticated Privilege Escalation in ajax_signupEPSS 0.4%CVE-2026-56216HIGHCapgo - Scope Escalation via API Key Creation in /functions/v1/apikeyEPSS 0.4%CVE-2026-65603HIGHGrav Login Plugin 3.8.11 Privilege Escalation via Profile UpdateEPSS 0.4%CVE-2026-6897HIGHWishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX actionEPSS 0.4%CVE-2026-81543HIGHAbandoned Cart Pro for WooCommerce <= 10.7.1 - Missing Authorization to Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2026-40291HIGHChamilo LMS has Privilege Escalation via API User Role ModificationEPSS 0.4%CVE-2026-6898HIGHWishList Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) Generate API Secret Key via 'wlm3_generate_api_key' AJAX actionEPSS 0.4%CVE-2026-58053CRITICALGitea act_runner - Container Hardening Bypass via Workflow Container OptionsEPSS 0.4%CVE-2026-67356HIGHArcadeDB before 26.7.3 Privilege Escalation via JavaScript TriggerEPSS 0.4%CVE-2026-12224HIGHDokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST EndpointEPSS 0.4%CVE-2021-4314MEDIUMIt is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. ThiEPSS 0.4%CVE-2026-57995HIGHphpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissionsEPSS 0.4%CVE-2026-13756HIGHWP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' ParameterEPSS 0.4%CVE-2026-75851CRITICALArcadeDB before 26.8.1 Authentication Bypass via Async CommandEPSS 0.4%