Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2022-38777HIGHAn issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate thEPSS 0.3%CVE-2023-38614MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be EPSS 0.3%CVE-2020-7324MEDIUMImproper Access Control vulnerability in MVISION EndpointEPSS 0.3%CVE-2022-1823HIGHMcAfee MCPR privilege escalationEPSS 0.3%CVE-2020-26181HIGHDell EMC Isilon OneFS versions 8.1 and later and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability on a SEPSS 0.3%CVE-2021-1371MEDIUMCisco IOS XE SD-WAN Software Console Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-66315MEDIUMZTE MF258K Pro Version Server has a Configuration Defect VulnerabilityEPSS 0.3%CVE-2024-47770MEDIUMAbility to view Agent list with no privilege access in wazuh-dashboardEPSS 0.3%CVE-2021-33526HIGHPrivilege escalation in mbDIALUP <= 3.9R0.0EPSS 0.3%CVE-2024-28851MEDIUMElevation of privilege in Snowflake Hive MetaStore Connector Helper scriptEPSS 0.3%CVE-2021-31833HIGHPotential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally loggEPSS 0.3%CVE-2024-56447HIGHVulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affecEPSS 0.3%CVE-2026-55226MEDIUMStrimzi: Unrestricted access to all Secrets within namespace watched by the Topic operatorEPSS 0.3%CVE-2020-16238MEDIUMB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 0.2%CVE-2025-3224HIGHElevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory DeletionEPSS 0.2%CVE-2021-37942HIGHAPM Java Agent Local Privilege EscalationEPSS 0.2%CVE-2026-13415HIGHCMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settingsEPSS 0.2%CVE-2026-16772HIGHCVE-2026-16772EPSS 0.2%CVE-2021-25336LOWImproper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applicationEPSS 0.2%CVE-2026-46424MEDIUMBudibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 HourEPSS 0.2%