Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2023-7342HIGHBelden HiSecOS Web Server Privilege EscalationEPSS 0.3%CVE-2025-68697HIGHSelf-hosted n8n has Legacy Code node that enables arbitrary file read/writeEPSS 0.3%CVE-2019-11288HIGHtcServer JMX Socket Listener Registry Rebinding Local Privilege EscalationEPSS 0.3%CVE-2020-6968—Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges through the modification of local configuratiEPSS 0.3%CVE-2025-50062HIGHVulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). SuppoEPSS 0.3%CVE-2019-18899MEDIUMapt-cacher-ng insecure use of /run/apt-cacher-ngEPSS 0.3%CVE-2022-42849HIGHAn access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 anEPSS 0.3%CVE-2021-22732—Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code executEPSS 0.3%CVE-2025-8309HIGHUser privilege escalation vulnerabilityEPSS 0.3%CVE-2026-62453MEDIUMVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affeEPSS 0.3%CVE-2026-62525MEDIUMVulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supported versions that EPSS 0.3%CVE-2026-61304MEDIUMVulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.3%CVE-2024-22069HIGHPermission and Access Control Vulnerability in ZXV10 XT802/ET301EPSS 0.3%CVE-2026-61216MEDIUMVulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2026-62524MEDIUMVulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affEPSS 0.3%CVE-2026-62474MEDIUMVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versionEPSS 0.3%CVE-2025-2324MEDIUMA MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folderEPSS 0.3%CVE-2023-38496MEDIUMApptainer's ineffective privileges drop when requesting container networkEPSS 0.3%CVE-2022-1256HIGHImproper Privilege Management in McAfee Agent for WindowsEPSS 0.3%CVE-2025-22621MEDIUMPrivilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAREPSS 0.3%