Fallos del tipo CWE-269

2507 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2026-46424MEDIUMBudibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 HourEPSS 0.2%CVE-2021-43768MEDIUMIn Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface runnEPSS 0.2%CVE-2025-0358HIGHDuring an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration fraEPSS 0.2%CVE-2023-3514HIGHRazerCentralSerivce Unsafe Named Pipe Permission Escalation of Privilege VulnerabilityEPSS 0.2%CVE-2023-25647MEDIUMPermission and Access Control Vulnerability in Some ZTE Mobile PhonesEPSS 0.2%CVE-2025-57759MEDIUMContao has improper privilege management for page and article fieldsEPSS 0.2%CVE-2025-26703MEDIUMImproper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1EPSS 0.2%CVE-2020-7281HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.2%CVE-2024-22237HIGHAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for NetworksEPSS 0.2%CVE-2026-100586HIGHOpenClaw Codex before 2026.7.1 Authorization Bypass via BindEPSS 0.2%CVE-2025-6759HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2020-7273MEDIUMAutorun registry bypassEPSS 0.2%CVE-2021-3809HIGHPotential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary EPSS 0.2%CVE-2021-3808HIGHPotential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary EPSS 0.2%CVE-2025-27468HIGHWindows Kernel-Mode Driver Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2023-52431HIGHThe Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form valEPSS 0.2%CVE-2021-31359HIGHJunos OS and Junos OS Evolved: Local Privilege Escalation vulnerabilityEPSS 0.2%CVE-2022-38774HIGHAn issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivilegEPSS 0.2%CVE-2025-36904CRITICALWLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.EPSS 0.2%CVE-2026-73779HIGHAuthentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CXEPSS 0.2%