Fallos del tipo CWE-269

2509 resultados

Gestão inadequada de privilégios

A aplicação não controla corretamente quais permissões um usuário ou processo possui, permitindo que ele acesse, modifique ou execute ações além do que deveria. Isso acontece quando a lógica de verificação de privilégios é fraca, ausente ou implementada de forma inconsistente, criando brechas onde um ator com poucos direitos consegue agir como se tivesse privilégios administrativos.

Ejemplo

Um sistema web onde o controle de acesso verifica se o usuário é admin apenas na tela inicial, mas não valida novamente ao processar requisições diretas de API. Um usuário comum consegue chamar endpoints administrativos diretamente, contornando a verificação.

Cómo mitigar

Implemente verificação de privilégios em **toda** operação sensível, não apenas na apresentação — valide no backend antes de executar qualquer ação. Use um modelo de controle de acesso consistente (RBAC ou ABAC), aplique o princípio do privilégio mínimo e revise regularmente quem tem acesso ao quê.

CVE-2022-39953HIGHA improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1EPSS 0.2%CVE-2026-11295HIGHInappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege esEPSS 0.2%CVE-2024-40460HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXEEPSS 0.2%CVE-2024-40458HIGHAn issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.EPSS 0.2%CVE-2021-24038—Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged pEPSS 0.2%CVE-2024-40462HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE componentEPSS 0.2%CVE-2023-6804MEDIUMImproper Privilege Management allows for arbitrary workflows to be runEPSS 0.2%CVE-2025-64487HIGHOutline is vulnerable to privilege escalation vulnerability in document sharingEPSS 0.2%CVE-2024-40461HIGHAn issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE componentEPSS 0.2%CVE-2024-23457HIGHAnti-tampering can be disabled with uninstall password enforcedEPSS 0.2%CVE-2024-40459HIGHAn issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager functionEPSS 0.2%CVE-2025-1424HIGHPrivilege Escalation Through SUID Binary and Developer ModeEPSS 0.2%CVE-2025-1732MEDIUMAn improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlieEPSS 0.2%CVE-2025-12425CRITICALLocal Privilege EscalationEPSS 0.2%CVE-2023-25535HIGH Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerabilityEPSS 0.2%CVE-2025-70795MEDIUMSTProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminEPSS 0.2%CVE-2023-24491HIGH A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with accEPSS 0.2%CVE-2026-33727MEDIUMPi-hole has a Local Privilege Escalation (post-compromise, pihole -> root).EPSS 0.2%CVE-2026-22804HIGHTermix has a Stored XSS in File Manager leading to Local File Inclusion (LFI) in Electron and Session Hijacking in BrowserEPSS 0.2%CVE-2018-9375HIGHIn multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confusEPSS 0.2%