Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-66782MEDIUMSubmariner-operator: operator clusterrole grants cluster-wide create/update on all configmapsEPSS 0.4%CVE-2026-31836HIGHMass Assignment Privilege Escalation in CheckmateEPSS 0.4%CVE-2026-15142HIGHReal Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID CollisionEPSS 0.4%CVE-2026-47416CRITICALpraisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}EPSS 0.4%CVE-2026-47413CRITICALpraisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/membersEPSS 0.4%CVE-2026-46899CRITICALVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions thEPSS 0.4%CVE-2024-22893HIGHOpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers EPSS 0.4%CVE-2024-1764HIGHImproper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continueEPSS 0.4%CVE-2024-21034MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.4%CVE-2026-32106MEDIUMStudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin AccountsEPSS 0.4%CVE-2026-86552MEDIUMA vulnerability that skips email ownership verification for account registration in ZTE SmartLife APPEPSS 0.4%CVE-2026-60854HIGHVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectEPSS 0.4%CVE-2025-4335HIGHWoocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.4%CVE-2025-24805HIGHLocal Privilege Escalation in MobSFEPSS 0.4%CVE-2024-46549HIGHAn issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonatingEPSS 0.4%CVE-2026-13152HIGHCustom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2022-29179HIGHImproper Privilege Management in CiliumEPSS 0.4%CVE-2026-75481HIGHSkyPilot Authentication Bypass via Service Account Role EscalationEPSS 0.4%CVE-2018-14791—Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable and library files on EPSS 0.4%CVE-2026-41163HIGHbubblewrap vulnerable to privilege escalation in setuid mode via ptraceEPSS 0.4%