Fallos del tipo CWE-269

2492 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2017-0934—Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection ofEPSS 1.3%CVE-2020-8258—Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15EPSS 1.3%CVE-2026-8206CRITICALKirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'EPSS 1.3%CVE-2023-48902CRITICALAn issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car dEPSS 1.3%CVE-2017-0935—Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection EPSS 1.3%CVE-2020-8021MEDIUMunauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build ServiceEPSS 1.3%CVE-2022-43138CRITICALDolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.EPSS 1.3%CVE-2022-29218HIGHUnauthorized takeover for new versions of some platform-specific gemsEPSS 1.3%CVE-2021-27657HIGHMetasys Improper Privilege ManagementEPSS 1.2%CVE-2026-7467HIGHRead More & Accordion <= 3.5.7 - Privilege Escalation via importDataEPSS 1.2%CVE-2024-31141MEDIUMApache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProviderEPSS 1.2%CVE-2023-41954HIGHWordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerabilityEPSS 1.2%CVE-2021-28814HIGHImproper Access Control Vulnerability in HelpdeskEPSS 1.2%CVE-2017-0932—Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation EPSS 1.2%CVE-2021-31581HIGHAkkadian Provisioning Manager Engine (PME) Shell Escape via 'vi' editor interfaceEPSS 1.2%CVE-2022-20361MEDIUMIn btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth StaEPSS 1.2%CVE-2022-42735HIGHApache ShenYu Admin ultra viresEPSS 1.2%CVE-2020-7509—A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow aEPSS 1.2%CVE-2018-19635—CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.EPSS 1.2%CVE-2026-7465HIGHSpectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block AttributesEPSS 1.2%