Fallos del tipo CWE-280

169 resultados

Tratamento inadequado de permissões ou privilégios insuficientes

A aplicação não verifica ou não reage corretamente quando um usuário tenta executar uma ação sem as permissões necessárias. Em vez de negar o acesso de forma segura, o sistema pode ignorar a falta de permissão, executar a operação parcialmente, ou deixar dados sensíveis expostos. Isso permite que usuários não autorizados acessem ou modifiquem recursos restritos.

Ejemplo

Um portal administrativo que tenta ocultar o botão 'Deletar usuário' via CSS para usuários comuns, mas não valida permissões no backend. Um atacante remove o CSS ou chama a API diretamente e consegue deletar qualquer usuário. Ou ainda: um sistema que registra um log quando acesso é negado, mas executa 80% da operação sensível antes de verificar permissões.

Cómo mitigar

Implemente validação de permissões no servidor (nunca confie no cliente) antes de qualquer operação sensível. Use um modelo de controle de acesso (RBAC, ABAC) consistente, valide permissões em toda camada de negócio, não apenas na UI, e falhe de forma segura — rejeite completamente a operação se houver dúvida sobre privilégios.

CVE-2025-25179HIGHGPU DDK - Freelist GPU VA can be remapped to another reservation/PMR to trigger GPU arbitrary write to physical memoryEPSS 0.1%CVE-2026-64701HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious aEPSS 0.1%CVE-2024-51459HIGHIBM InfoSphere Server Information command executionEPSS 0.1%CVE-2022-22292HIGHUnprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.EPSS 0.1%CVE-2025-46584HIGHVulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation of this vulnerabilitEPSS 0.1%CVE-2024-8315MEDIUMImproper Handling of Insufficient Permissions or Privileges in B&R APROLEPSS 0.1%CVE-2026-21736MEDIUMGPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabledEPSS 0.1%CVE-2026-46054HIGHselinux: fix overlayfs mmap() and mprotect() access checksEPSS 0.1%CVE-2025-58770HIGHTCG2 TPM RT Not Locked IssueEPSS 0.1%CVE-2022-39912MEDIUMImproper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows EPSS 0.1%CVE-2026-84631HIGHThis issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root prEPSS 0.1%CVE-2025-31173HIGHMemory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect serEPSS 0.1%CVE-2025-31172HIGHMemory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect serEPSS 0.1%CVE-2026-86917HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahoeEPSS 0.1%CVE-2022-30725MEDIUMBroadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of BluetEPSS 0.1%CVE-2022-30724MEDIUMBroadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of BEPSS 0.1%CVE-2022-30723MEDIUMBroadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice functEPSS 0.1%CVE-2025-27521MEDIUMVulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affecEPSS 0.1%CVE-2025-45376HIGHDell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Privileges vulnerabiliEPSS 0.1%CVE-2026-59567HIGHLocal privilege escalationEPSS 0.1%