Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-46935HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-46934HIGHVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). SEPSS 0.3%CVE-2026-60943HIGHVulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versiEPSS 0.3%CVE-2026-60855HIGHVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectEPSS 0.3%CVE-2026-87139HIGHVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.3%CVE-2026-60619HIGHVulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base). The sEPSS 0.3%CVE-2026-61188HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The sEPSS 0.3%CVE-2026-86554MEDIUMEmail enumeration and account ID leakage vulnerabilities in ZTE SmartLife APPEPSS 0.3%CVE-2026-9918CRITICALInappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escEPSS 0.3%CVE-2024-21985HIGHPrivilege Escalation Vulnerability in ONTAP 9 EPSS 0.3%CVE-2026-12470HIGHCMP <= 4.1.17 - Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX ActionEPSS 0.3%CVE-2026-17868HIGHInsufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation viaEPSS 0.3%CVE-2025-8218HIGHReal Spaces - WordPress Properties Directory Theme <= 3.5 - Authenticated (Subscriber+) Privilege Escalation to Administrator via 'change_role_member'EPSS 0.3%CVE-2023-4834MEDIUMIn Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implementEPSS 0.3%CVE-2023-47715MEDIUMIBM Storage Protect Plus Server improper access controlEPSS 0.3%CVE-2026-72631MEDIUMImproper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API KeysEPSS 0.3%CVE-2022-43997HIGHIncorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficEPSS 0.3%CVE-2023-39520MEDIUMCryptomator vulnerable to Local Elevation of PrivilegesEPSS 0.3%CVE-2024-55631HIGHAn engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installationsEPSS 0.3%CVE-2024-45919MEDIUMA security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the RequeEPSS 0.3%