Fallos del tipo CWE-269

2508 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2021-27483—ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilegEPSS 0.2%CVE-2023-23497—A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey EPSS 0.2%CVE-2026-61064MEDIUMVulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supported versions that EPSS 0.2%CVE-2022-36088MEDIUMGoCD Windows installations outside default location inadequately restrict installation file permissionsEPSS 0.2%CVE-2021-34745HIGHAppDynamics .NET Agent Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-54560MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A maliEPSS 0.2%CVE-2026-62355MEDIUMTDengine: Standard User permission unexpectEPSS 0.2%CVE-2025-52599MEDIUMInadequate account permissions managementEPSS 0.2%CVE-2022-31594—A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.EPSS 0.2%CVE-2026-88764MEDIUMSimple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_refEPSS 0.2%CVE-2025-12726HIGHInappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the EPSS 0.2%CVE-2023-31005MEDIUMIBM Security Access Manager Container privilege escalationEPSS 0.2%CVE-2025-6042HIGHLisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - Unauthenticated Privilege Escalation to EditorEPSS 0.2%CVE-2020-36549HIGHGE Voluson S8 Windows Operating System Patches privileges managementEPSS 0.2%CVE-2026-100578HIGHOpenClaw before 2026.7.1 Authorization Bypass via chat.sendEPSS 0.2%CVE-2018-16497—In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job EPSS 0.2%CVE-2024-26314HIGHImproper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary coEPSS 0.2%CVE-2025-32955MEDIUMHarden-Runner Evasion of 'disable-sudo' policyEPSS 0.2%CVE-2021-25418—Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrarEPSS 0.2%CVE-2020-15934HIGHAn execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. mEPSS 0.2%