Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-9471MEDIUMPAN-OS: Privilege Escalation (PE) Vulnerability in XML APIEPSS 0.3%CVE-2020-26191HIGHDell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the PEPSS 0.3%CVE-2020-7310MEDIUMPrivilege Escalation vulnerability in McAfee Total Protection (MTP) trial installerEPSS 0.3%CVE-2026-44119MEDIUMApache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modulesEPSS 0.3%CVE-2025-53026MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.3%CVE-2026-9892HIGHInappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the rEPSS 0.3%CVE-2026-17816HIGHInsufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2022-24077—Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.EPSS 0.3%CVE-2026-86746HIGHSnipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot ReplayEPSS 0.3%CVE-2025-53025MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.3%CVE-2021-23880MEDIUMImproper Access Control in the ENS installerEPSS 0.3%CVE-2026-77699MEDIUMPrivilege EscalationEPSS 0.3%CVE-2023-41053LOWRedis SORT_RO may bypass ACL configurationEPSS 0.3%CVE-2022-32781MEDIUMThis issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security UpdateEPSS 0.3%CVE-2026-12878HIGHIn affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.EPSS 0.3%CVE-2024-46989LOWMultiple caveats on resources of the same type can result in no permission when permission is expectedEPSS 0.3%CVE-2019-3588MEDIUMUsing VSE to bypass Windows Credentials on Lock screenEPSS 0.3%CVE-2024-52336HIGHTuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by rootEPSS 0.3%CVE-2026-62456HIGHVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2026-33706HIGHChamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher)EPSS 0.3%