Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-56239HIGHCapgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overageEPSS 0.3%CVE-2026-93901HIGHOptima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role AssignmentEPSS 0.3%CVE-2026-77698MEDIUMPrivilege EscalationEPSS 0.3%CVE-2026-23896HIGHimmich API Key Privilege Escalation vulnerabilityEPSS 0.3%CVE-2023-43663MEDIUMImproper Privilege Management in PrestashopEPSS 0.3%CVE-2025-43333HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to gain root priviEPSS 0.3%CVE-2023-30601HIGHApache Cassandra: Privilege escalation when enabling FQL/Audit logsEPSS 0.3%CVE-2023-41036HIGHMacvim's Insecure Usage of IPC MechanismsEPSS 0.3%CVE-2025-70887HIGHAn issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py componeEPSS 0.3%CVE-2026-60492HIGHVulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundation). The supported EPSS 0.3%CVE-2023-23412HIGHWindows Accounts Picture Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-3513HIGHRazerCentralService Unsafe Deserialization Escalation of PrivilegeEPSS 0.3%CVE-2023-53908HIGHHiSecOS 04.0.01 Privilege Escalation via User Role ModificationEPSS 0.3%CVE-2026-1010HIGHStored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege EscalationEPSS 0.3%CVE-2026-56212MEDIUMCapgo - Improper 2FA Enforcement Logic via Team Security SettingsEPSS 0.3%CVE-2020-3393MEDIUMCisco IOS XE Software IOx Application Hosting Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-15630CRITICALCVE-2026-15630EPSS 0.3%CVE-2021-23891HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.3%CVE-2023-23427MEDIUM Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2022-24927MEDIUMImproper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files withoEPSS 0.3%