Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2020-7544—A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause prEPSS 0.3%CVE-2024-22795HIGHInsecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the RechecEPSS 0.3%CVE-2026-83241HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). TheEPSS 0.3%CVE-2025-25202MEDIUMAsh Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`EPSS 0.3%CVE-2026-5193MEDIUMEssential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_userEPSS 0.3%CVE-2025-6366HIGHEvent List <= 2.0.4 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2023-46810HIGHA local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute cEPSS 0.3%CVE-2013-10052HIGHZPanel zsudo Local Privilege EscalationEPSS 0.3%CVE-2025-45737MEDIUMAn issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafteEPSS 0.3%CVE-2026-14805HIGHConsulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAXEPSS 0.3%CVE-2025-54996HIGHOpenBao Root Namespace Operator May Elevate Token PrivilegesEPSS 0.3%CVE-2024-2003HIGHLocal Privilege Escalation in Quarantine of ESET products for WindowsEPSS 0.3%CVE-2025-59697HIGHEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.3%CVE-2026-100615HIGHCap-go capgo.app before 12.267.1 Privilege Escalation via API Key RotationEPSS 0.3%CVE-2026-73755MEDIUMPrivilege Escalation via Unauthorized Access to Sensitive Session InformationEPSS 0.3%CVE-2023-0664HIGHA flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's WinEPSS 0.3%CVE-2026-48210MEDIUMPossible information disclosure via External InterfaceEPSS 0.3%CVE-2023-23430LOW Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2025-8660MEDIUMPrivilege Escalation in Symantec PGP Encryption 11.0.1EPSS 0.3%CVE-2023-23428LOW Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%