Falhas do tipo CWE-1220

115 resultados

Controle de acesso com granularidade insuficiente

Ocorre quando um sistema concede permissões em nível muito amplo, sem distinção entre diferentes tipos de operações, recursos ou usuários. Por exemplo, dar acesso total a um módulo quando o usuário precisava apenas ler dados, ou permitir qualquer ação em uma API sem segregar por funcionalidade. Isso amplifica o dano de uma credencial comprometida ou de um usuário mal-intencionado.

Exemplo

Um sistema de gestão de documentos que permite 'administrador' ou 'usuário', quando na verdade deveria ter papéis como 'leitor', 'editor', 'aprovador' e 'gerenciador de usuários'. Se um atacante compromete uma conta de 'usuário', pode fazer tudo que qualquer outro 'usuário' faz — inclusive deletar documentos críticos que só deveria poder ler.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC) ou atributos (ABAC) com permissões específicas e mínimas: defina exatamente quem pode ler, editar, deletar ou transferir cada tipo de recurso. Revise regularmente essas permissões e remova acessos desnecessários durante offboarding ou mudanças de função.

CVE-2025-2498LOWInsufficient Granularity of Access Control in GitLabEPSS 0.3%CVE-2025-8053LOWInsufficient access control vulnerability has been discovered in Opentext Flipper.EPSS 0.3%CVE-2026-69267MEDIUMWindows Connected User Experiences and Telemetry Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-0873MEDIUMPrivilege Elevation in Ercom Cryptobox administration consoleEPSS 0.2%CVE-2026-78216MEDIUMAshLua eval read operations can read field-policy-protected fields via aggregatesEPSS 0.2%CVE-2026-78230MEDIUMAshAi aggregate tool can read field-policy-protected fieldsEPSS 0.2%CVE-2024-13272MEDIUMParagraphs table - Critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-036EPSS 0.2%CVE-2025-20628MEDIUMInsufficient granularity of access control for Remote Connector Servers in client modeEPSS 0.2%CVE-2023-44285HIGH Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability.EPSS 0.2%CVE-2026-35436HIGHMicrosoft Office Click-To-Run Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2024-39279MEDIUMInsufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enableEPSS 0.2%CVE-2026-16108MEDIUMKeycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2EPSS 0.2%CVE-2024-52799HIGHArgo Workflows Chart: Excessive Privileges in Workflow RoleEPSS 0.2%CVE-2023-6725MEDIUMTripleo-ansible: bind keys are world readableEPSS 0.2%CVE-2023-45217HIGHImproper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escEPSS 0.2%CVE-2023-40070HIGHImproper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable EPSS 0.2%CVE-2025-22839HIGHInsufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potEPSS 0.2%CVE-2023-31343HIGHImproper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execuEPSS 0.2%CVE-2023-31342HIGHImproper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execuEPSS 0.2%CVE-2024-52814LOWHelm Lacks Granularity in Workflow RoleEPSS 0.2%