Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-8660MEDIUMPrivilege Escalation in Symantec PGP Encryption 11.0.1EPSS 0.3%CVE-2023-23428LOW Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2026-8327MEDIUMConcrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.EPSS 0.3%CVE-2023-25144HIGHAn improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and creaEPSS 0.3%CVE-2024-41228HIGHA symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges anEPSS 0.3%CVE-2024-6325MEDIUMRockwell Automation Unsecured Private Keys in FactoryTalk® System ServicesEPSS 0.3%CVE-2025-58053MEDIUMGalette has a privilege escalation vulnerabilityEPSS 0.3%CVE-2026-43886HIGHOutline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API AccessEPSS 0.3%CVE-2026-17472CRITICALMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.3%CVE-2026-50295MEDIUMWindows Zero Trust DNS Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2025-26705MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.3%CVE-2025-5689HIGHImproper Permission Management in SSH Session HandlingEPSS 0.3%CVE-2026-33552LOWNorthern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.EPSS 0.3%CVE-2025-4085HIGHPotential information leakage and privilege escalation in UITour actorEPSS 0.3%CVE-2022-42796HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be aEPSS 0.3%CVE-2025-24863MEDIUMImproper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow aEPSS 0.3%CVE-2026-62565HIGHVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affeEPSS 0.3%CVE-2020-7254HIGHPrivilege escalation in Advanced Threat DefenseEPSS 0.3%CVE-2026-15354CRITICALACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' ParameterEPSS 0.3%CVE-2026-1566HIGHLatePoint <= 5.2.7 - Authenticated (Agent+) Privilege EscalationEPSS 0.3%