Fallos del tipo CWE-269

2508 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-54652HIGHFrigate viewer can read logs exposing admin and camera credentialsEPSS 0.4%CVE-2026-56225HIGHCapgo - Authorization Bypass in API Key Management via App-Limited KeysEPSS 0.4%CVE-2024-42774HIGHAn Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unaEPSS 0.4%CVE-2024-47000HIGHService Users Deactivation not Working in ZitadelEPSS 0.4%CVE-2024-23253HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a useEPSS 0.4%CVE-2026-44231CRITICALRT: Privilege escalation and information disclosure via REST 2.0 user collection endpointEPSS 0.4%CVE-1999-0084HIGHCertain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.EPSS 0.4%CVE-2024-5909MEDIUMCortex XDR Agent: Local Windows User Can Disable the AgentEPSS 0.4%CVE-2025-59790MEDIUMApache Kvrocks: RESET command grants admin privilegesEPSS 0.4%CVE-2026-5141HIGHImproper Access Control in TUBITAK BILGEM's Pardus Software CenterEPSS 0.4%CVE-2025-23208HIGHIdP group membership revocation ignored in zotEPSS 0.4%CVE-2024-36046CRITICALInfoblox NIOS through 8.6.4 executes with more privileges than required.EPSS 0.4%CVE-2023-44106—API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perforEPSS 0.4%CVE-2023-44105—Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cEPSS 0.4%CVE-2025-6994CRITICALReveal Listing <= 3.3 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2026-9999HIGHInappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inEPSS 0.4%CVE-2012-10022HIGHKloxo <= 6.1.12 Local Privilege EscalationEPSS 0.4%CVE-2018-14828—Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files EPSS 0.4%CVE-2026-16764MEDIUMOWASP DefectDojo API/Web serializers.py UserSerializer privileges managementEPSS 0.4%CVE-2026-60941HIGHVulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versiEPSS 0.4%