Fallos del tipo CWE-274

42 resultados

Escalação de privilégio

É quando um atacante consegue obter permissões ou acesso mais altos do que deveria ter na aplicação ou sistema. O código falha em validar adequadamente quem pode realizar certas ações, permitindo que um usuário comum acesse funcionalidades administrativas ou dados de outros usuários.

Ejemplo

Um usuário logado como 'cliente' manipula um parâmetro de URL (ex: user_id=1) para acessar dados ou funções reservadas ao administrador, porque a aplicação nunca verificou se esse usuário realmente tem permissão para tal operação.

Cómo mitigar

Implemente controle de acesso em todos os pontos sensíveis: valide a identidade e permissões do usuário antes de cada ação administrativo ou de dados. Use padrões como RBAC (controle por papéis) ou ABAC (controle por atributos), e revise regularmente quem tem acesso a quê.

CVE-2021-35534HIGHInsufficient Security Control VulnerabilityEPSS 1.7%CVE-2025-20156CRITICALCisco Meeting Management Client-Server Privilege Escalation VulnerabilityEPSS 1.2%CVE-2023-35928HIGHNextcloud user scoped external storage can be used to gather credentials of other usersEPSS 1.0%CVE-2022-45101HIGH Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthentiEPSS 0.8%CVE-2021-32006MEDIUMGateManager information leak for LinkManager UsersEPSS 0.6%CVE-2022-0668MEDIUMJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted rEPSS 0.6%CVE-2023-39375HIGHSiberianCMS - CWE-274: Improper Handling of Insufficient PrivilegesEPSS 0.6%CVE-2020-7283HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.6%CVE-2024-41942HIGHJupyterHub has a privilege escalation vulnerability with the `admin:users` scopeEPSS 0.6%CVE-2024-21648HIGHXWiki has no right protection on rollback actionEPSS 0.5%CVE-2025-29365CRITICALspimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.EPSS 0.5%CVE-2024-12666MEDIUMClassCMS User Management Page admin insufficient privilegesEPSS 0.5%CVE-2022-23160MEDIUMDell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An remote malicious usEPSS 0.5%CVE-2022-23511HIGHA privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2EPSS 0.5%CVE-2022-25782MEDIUMInsufficient privilege checks on object access and updates.EPSS 0.5%CVE-2026-33005MEDIUMApache OpenMeetings: Insufficient checks in FileWebServiceEPSS 0.4%CVE-2017-3912MEDIUMMcAfee Application Control and Change Control (MACC) - password management security feature bypass (SFB) leading to an authentication bypassEPSS 0.4%CVE-2020-24676HIGHInsecure Windows Services in Symphony PlusEPSS 0.4%CVE-2020-7289HIGHPrivilege Escalation vulnerability in MAR for WindowsEPSS 0.3%CVE-2026-62764MEDIUMApache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissionsEPSS 0.3%