Fallos del tipo CWE-269

2510 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-61013MEDIUMVulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2025-25872MEDIUMAn issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions functionEPSS 0.3%CVE-2026-16366HIGHPrivilege escalation in the DOM: Navigation componentEPSS 0.3%CVE-2026-73842CRITICALOpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutationEPSS 0.3%CVE-2022-32826HIGHAn authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, EPSS 0.3%CVE-2025-20346MEDIUMCisco Catalyst Center Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-5494LOWPrivilege EscalationEPSS 0.3%CVE-2026-56733HIGHZammad: Incorrect Authorization and Improper Privilege ManagementEPSS 0.3%CVE-2026-60371HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-31284MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to EPSS 0.3%CVE-2025-31285MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator EPSS 0.3%CVE-2026-75924HIGHManaged-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants cluster-wide secret read/write and csr approvalEPSS 0.3%CVE-2025-31282MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administratEPSS 0.3%CVE-2025-31283MEDIUMA broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administratorEPSS 0.3%CVE-2024-45752HIGHlogiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus seEPSS 0.3%CVE-2026-44987LOWSysReptor: Privilege Escalation from User Admin to SuperuserEPSS 0.3%CVE-2025-68697HIGHSelf-hosted n8n has Legacy Code node that enables arbitrary file read/writeEPSS 0.3%CVE-2023-7342HIGHBelden HiSecOS Web Server Privilege EscalationEPSS 0.3%CVE-2023-24483HIGHPrivilege Escalation to NT AUTHORITY\SYSTEM on the vulnerable VDAEPSS 0.3%CVE-2019-11288HIGHtcServer JMX Socket Listener Registry Rebinding Local Privilege EscalationEPSS 0.3%