Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2025-61429HIGHAn issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request.EPSS 0.3%CVE-2025-67781CRITICALAn issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulateEPSS 0.3%CVE-2023-41076HIGHAn app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.EPSS 0.3%CVE-2022-24750HIGHLow privilege user is able to exploit the service and gain SYSTEM privileges in UltraVNC serverEPSS 0.3%CVE-2025-24838HIGHImproper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow aEPSS 0.3%CVE-2025-13292HIGHImproper access control in Google Cloud Apigee-X allows cross-tenant Analytics modification and log data access.EPSS 0.3%CVE-2021-1447MEDIUMCisco Content Security Management Appliance Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-11616HIGHEvents Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege EscalationEPSS 0.3%CVE-2026-18702MEDIUMImproper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic SettingsEPSS 0.3%CVE-2025-2858HIGHPrivilege escalation vulnerability in saTECH BCUEPSS 0.3%CVE-2020-35593—BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.EPSS 0.3%CVE-2024-6359MEDIUMPrivilege escalation vulnerabilityEPSS 0.3%CVE-2026-46696LOWOctober CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder CallsEPSS 0.3%CVE-2026-97895MEDIUMkrayin laravel-crm User Management UserController.php privileges managementEPSS 0.3%CVE-2026-21963MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.EPSS 0.3%CVE-2025-13534MEDIUMELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX ActionEPSS 0.3%CVE-2025-7044HIGHPrivilege Escalation in MAAS via Websocket Request ManipulationEPSS 0.3%CVE-2026-61013MEDIUMVulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2026-87164HIGHVulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that EPSS 0.3%CVE-2026-70443MEDIUMJenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackerEPSS 0.3%