Fallos del tipo CWE-269

2508 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2024-44439MEDIUMAn issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allowsEPSS 0.2%CVE-2025-43249HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An aEPSS 0.2%CVE-2025-43248HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may EPSS 0.2%CVE-2022-43533HIGH A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A suEPSS 0.2%CVE-2023-5960MEDIUMAn improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VEPSS 0.2%CVE-2025-36891HIGHElevation of privilegeEPSS 0.2%CVE-2021-23887HIGHPrivilege escalation in McAfee DLP Endpoint for WindowsEPSS 0.2%CVE-2025-27644HIGHVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-0EPSS 0.2%CVE-2021-27445HIGHMesa Labs AmegaView Improper Privilege ManagementEPSS 0.2%CVE-2024-28241HIGHGlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folderEPSS 0.2%CVE-2024-44540MEDIUMUbiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART DeEPSS 0.2%CVE-2024-43446LOWImproper check of permissions in Generic InterfaceEPSS 0.2%CVE-2026-84358MEDIUMImproper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2024-12786HIGHX1a0He Adobe Downloader XPC Service com.x1a0he.macOS.Adobe-Downloader.helper shouldAcceptNewConnection privileges managementEPSS 0.2%CVE-2021-22733—Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access EPSS 0.2%CVE-2026-16401HIGHPrivilege escalation in the Data Loss Prevention componentEPSS 0.2%CVE-2025-50064MEDIUMVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.2%CVE-2024-6151HIGHLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesEPSS 0.2%CVE-2025-31243HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS VenturEPSS 0.2%CVE-2023-5650MEDIUMAn improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmEPSS 0.2%