Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2023-7016HIGHPrivilege Escalation in SafeNet Authentication Client EPSS 0.3%CVE-2022-24927MEDIUMImproper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files withoEPSS 0.3%CVE-2023-28640MEDIUMPermissions bypass in Apiman could enable authenticated attacker to unpermitted API KeyEPSS 0.3%CVE-2022-48019HIGHThe components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to perform privilege escalEPSS 0.3%CVE-2024-53706HIGHA vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges toEPSS 0.3%CVE-2020-16122HIGHPackagekit's apt backend lets user install untrusted local packagesEPSS 0.3%CVE-2021-27765MEDIUMHCL BigFix Platform Server API is affected by Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-55550HIGHNextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product CatalogEPSS 0.3%CVE-2025-14975HIGHCustom Login Page Customizer < 2.5.4 - Unauthenticated Arbitrary Password ResetEPSS 0.3%CVE-2026-73724HIGHAuthenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric ComposerEPSS 0.3%CVE-2024-56335HIGHPrivilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwardenEPSS 0.3%CVE-2025-64489HIGHSuiteCRM: Privilege Escalation via Improper Session Invalidation and Inactive User BypassEPSS 0.3%CVE-2023-50267MEDIUMMeterSphere horizontal privilege escalation vulnerability of resources in project scope.EPSS 0.3%CVE-2024-48729HIGHAn issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote authenticated attackeEPSS 0.3%CVE-2026-62515HIGHVulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). SupportedEPSS 0.3%CVE-2022-30121MEDIUMThe “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executablesEPSS 0.3%CVE-2025-13618CRITICALMentoring <= 1.2.8 - Unauthenticated Privilege Escalation in mentoring_process_registrationEPSS 0.3%CVE-2026-47411MEDIUMpraisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}EPSS 0.3%CVE-2023-21990HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PrioEPSS 0.3%CVE-2026-30874LOWOpenWrt procd PATH Environment Variable Filter Bypass via Incorrect String Comparison Leads to Privilege EscalationEPSS 0.3%