Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-19360MEDIUMwongcyrus ExcelLexBot Lambda Function ExcelLexBotS3TriggerFunction privileges managementEPSS 0.4%CVE-2023-38058MEDIUMTickets can be moved without permissionsEPSS 0.4%CVE-2023-27651HIGHAn issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info field of the _default_EPSS 0.4%CVE-2026-35291MEDIUMVulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.EPSS 0.4%CVE-2025-13787MEDIUMZenTao File control.php delete privileges managementEPSS 0.4%CVE-2025-12952HIGHPrivilege Escalation in Dialogflow CX via Webhook Admin RoleEPSS 0.4%CVE-2023-5214MEDIUMCVE-2023-5214 - Privilege Escalation in Puppet Bolt EPSS 0.4%CVE-2026-27802HIGHVaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections by ManagerEPSS 0.4%CVE-2026-27803HIGHVaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager RoleEPSS 0.4%CVE-2026-83245HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-83169HIGHVulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). Supported versions tEPSS 0.4%CVE-2026-83464HIGHVulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versioEPSS 0.4%CVE-2026-83256HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-80467HIGHAdvanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privilege Escalation via Front-End User Insert ActionEPSS 0.4%CVE-2026-32212MEDIUMUniversal Plug and Play (upnp.dll) Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-83254HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-83351HIGHVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploEPSS 0.4%CVE-2026-83255HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.4%CVE-2026-83191HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.4%CVE-2026-68830MEDIUMWindows Universal Plug and Play (UPnP) Device Host Information Disclosure VulnerabilityEPSS 0.4%