Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2023-25834MEDIUMBUG-000142922 Incomplete permission changes in specific cases.EPSS 0.3%CVE-2026-83292HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported EPSS 0.3%CVE-2026-83489HIGHVulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding Batch Processes). EPSS 0.3%CVE-2026-83289HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). SupporEPSS 0.3%CVE-2026-83263HIGHVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.3%CVE-2025-5088HIGHArista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis SessionEPSS 0.3%CVE-2026-86406HIGHUser Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership PurchaseEPSS 0.3%CVE-2026-76396HIGHImproper Access Control through Scheduled Searches in Splunk AI ToolkitEPSS 0.3%CVE-2026-83257HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2026-83296HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versionsEPSS 0.3%CVE-2026-83295HIGHVulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). SupporEPSS 0.3%CVE-2026-83272HIGHVulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and EPSS 0.3%CVE-2026-83451HIGHVulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that EPSS 0.3%CVE-2026-83318HIGHVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are EPSS 0.3%CVE-2025-61152MEDIUMpython-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A maliEPSS 0.3%CVE-2026-83114HIGHVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affectEPSS 0.3%CVE-2026-83262HIGHVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.3%CVE-2025-13851CRITICALBuyent Theme (with Buyent Classified Plugin) <= 1.0.7 - Unauthenticated Privilege Escalation via User RegistrationEPSS 0.3%CVE-2026-11423CRITICALPath Traversal in Altium Enterprise Server Collaboration Service Allows Privilege EscalationEPSS 0.3%CVE-2025-3438MEDIUMMStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege EscalationEPSS 0.3%