Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2022-43308HIGHINTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.EPSS 0.3%CVE-2023-23429MEDIUM Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptEPSS 0.3%CVE-2026-48926MEDIUMJenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with OEPSS 0.3%CVE-2026-7778MEDIUMrunZero Platform dashboard configuration exposureEPSS 0.3%CVE-2026-48923MEDIUMJenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackersEPSS 0.3%CVE-2026-77003LOWContent Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_content_maskEPSS 0.3%CVE-2026-2375MEDIUMApp Builder – Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' ParameterEPSS 0.3%CVE-2018-10502—This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 4.2.18.EPSS 0.3%CVE-2026-30888LOWDiscourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpointEPSS 0.3%CVE-2025-26707MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.3%CVE-2020-7311HIGHPrivilege Escalation vulnerability in MA for WindowsEPSS 0.3%CVE-2026-16379HIGHPrivilege escalation in the DOM: Content Processes componentEPSS 0.3%CVE-2026-61549CRITICALWoodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backendEPSS 0.3%CVE-2026-16365HIGHPrivilege escalation in the DOM: Workers componentEPSS 0.3%CVE-2026-1750HIGHEcwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 - Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_accessEPSS 0.3%CVE-2026-16259CRITICALUix UserCenter <= 1.0.3 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2026-92015HIGHPrivilege escalation in the WebExtensions componentEPSS 0.3%CVE-2023-52114HIGHData confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.EPSS 0.3%CVE-2025-24838HIGHImproper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow aEPSS 0.3%CVE-2025-67781CRITICALAn issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulateEPSS 0.3%