Fallos del tipo CWE-280

169 resultados

Tratamento inadequado de permissões ou privilégios insuficientes

A aplicação não verifica ou não reage corretamente quando um usuário tenta executar uma ação sem as permissões necessárias. Em vez de negar o acesso de forma segura, o sistema pode ignorar a falta de permissão, executar a operação parcialmente, ou deixar dados sensíveis expostos. Isso permite que usuários não autorizados acessem ou modifiquem recursos restritos.

Ejemplo

Um portal administrativo que tenta ocultar o botão 'Deletar usuário' via CSS para usuários comuns, mas não valida permissões no backend. Um atacante remove o CSS ou chama a API diretamente e consegue deletar qualquer usuário. Ou ainda: um sistema que registra um log quando acesso é negado, mas executa 80% da operação sensível antes de verificar permissões.

Cómo mitigar

Implemente validação de permissões no servidor (nunca confie no cliente) antes de qualquer operação sensível. Use um modelo de controle de acesso (RBAC, ABAC) consistente, valide permissões em toda camada de negócio, não apenas na UI, e falhe de forma segura — rejeite completamente a operação se houver dúvida sobre privilégios.

CVE-2024-47767MEDIUMTuleap lists trackers in the quick add actions of the backlog without any permissions checkEPSS 0.4%CVE-2025-6573CRITICALGPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/OverwriteEPSS 0.4%CVE-2023-2020MEDIUMUnauthorized scheduling of downtimes via REST APIEPSS 0.4%CVE-2025-8109HIGHGPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operationEPSS 0.4%CVE-2025-50170HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-46874CRITICALRuijie Reyee OS Improper Handling of Insufficient Permissions or PrivilegesEPSS 0.4%CVE-2025-49731LOWMicrosoft Teams Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-36112MEDIUMNautobot dynamic-group-members doesn't enforce permission restrictions on member objectsEPSS 0.4%CVE-2025-67848HIGHMoodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.EPSS 0.4%CVE-2022-34368MEDIUMDell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Permissions or PrivilegEPSS 0.4%CVE-2024-4468MEDIUMSalon booking system <= 9.9 - Missing AuthorizationEPSS 0.4%CVE-2024-0015HIGHIn convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. EPSS 0.4%CVE-2025-22256MEDIUMA improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1EPSS 0.4%CVE-2026-41566CRITICALApache Kvrocks: Improper permission for the APPLYBATCH commandEPSS 0.4%CVE-2023-52537HIGHVulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will afEPSS 0.4%CVE-2025-27024MEDIUMImproper File Access in Infinera G42EPSS 0.4%CVE-2024-46988MEDIUMTuleap does not properly check permissions for email notifications in trackersEPSS 0.4%CVE-2025-24029MEDIUMArtifact permissions are not verified in the Cross Tracker Search widget in TuleapEPSS 0.4%CVE-2024-30418HIGHVulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability wiEPSS 0.4%CVE-2026-73239MEDIUMApache Allura: Missing permission checks IDOREPSS 0.3%