Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-27301HIGHPrivilege Escalation Abusing installer in SupportAppEPSS 0.3%CVE-2025-50069HIGHVulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. EasiEPSS 0.3%CVE-2025-3438MEDIUMMStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege EscalationEPSS 0.3%CVE-2026-68821HIGHWindows Package Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-20308MEDIUMCisco IOS XE Software Web-Based Management Interface VulnerabilityEPSS 0.3%CVE-2023-50677HIGHAn issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cEPSS 0.3%CVE-2024-47853HIGHAn issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into MahEPSS 0.3%CVE-2025-6080HIGHWPGYM <= 67.7.0 - Missing Authorization to Admin Account CreationEPSS 0.3%CVE-2026-60342MEDIUMVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.3%CVE-2023-52107HIGHVulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect serviceEPSS 0.3%CVE-2025-12424CRITICALPrivilege Escalation through SUID-bit BinaryEPSS 0.3%CVE-2025-67793CRITICALAn issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permEPSS 0.3%CVE-2025-54761HIGHAn issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.EPSS 0.3%CVE-2018-17954CRITICALcrowbar provision leaks admin password to all nodes in cleartextEPSS 0.3%CVE-2024-6240HIGHImproper privilege management vulnerability in Parallels DesktopEPSS 0.3%CVE-2023-46756—Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up wEPSS 0.3%CVE-2025-11168HIGHMementor Core <= 2.2.5 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2026-73714HIGHAuthenticated Sensitive Information Disclosure in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2026-16071MEDIUMKeycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundaryEPSS 0.3%CVE-2026-45801MEDIUMGLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)EPSS 0.3%