Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-21141HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PrioEPSS 0.3%CVE-2025-64436MEDIUMKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between NodesEPSS 0.3%CVE-2025-22621MEDIUMPrivilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAREPSS 0.3%CVE-2024-3507HIGHPrivilege escalation vulnerability in LunarEPSS 0.3%CVE-2024-31320HIGHIn setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation dEPSS 0.3%CVE-2024-27207CRITICALExported broadcast receivers allowing malicious apps to bypass broadcast protection.EPSS 0.3%CVE-2024-27826HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma EPSS 0.3%CVE-2026-83170HIGHVulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are aEPSS 0.3%CVE-2021-25657HIGHAvaya IP Office Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-50066LOWVulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-1EPSS 0.3%CVE-2024-32849HIGHTrend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionaEPSS 0.3%CVE-2024-37364MEDIUMAriane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensiEPSS 0.3%CVE-2026-17952HIGHInappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious eEPSS 0.3%CVE-2025-12405HIGHUnauthorized access through stored credentials in Looker StudioEPSS 0.3%CVE-2022-32782MEDIUMThis issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able tEPSS 0.3%CVE-2020-27352CRITICALWhen generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result sEPSS 0.3%CVE-2023-38614MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be EPSS 0.3%CVE-2026-12448HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege eEPSS 0.3%CVE-2026-92017HIGHPrivilege escalation in the DOM: Service Workers componentEPSS 0.3%CVE-2022-38777HIGHAn issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate thEPSS 0.3%