Falhas do tipo CWE-250

370 resultados

Execução com privilégios desnecessários

A aplicação ou processo executa com mais permissões (root, admin, service account privilegiado) do que realmente precisa para suas funções. Quando explorada, uma vulnerabilidade no código ganha acesso elevado, permitindo ao atacante comprometer todo o sistema ou dados sensíveis que só aquele nível de privilégio poderia acessar.

Exemplo

Um serviço web que apenas lê arquivos de configuração e envia emails roda como root. Uma injeção SQL nesse serviço não daria acesso apenas ao banco de dados, mas permitiria ao atacante criar usuários do SO, desabilitar firewalls ou acessar qualquer arquivo do servidor.

Como mitigar

Execute sempre com o menor nível de privilégio necessário — crie contas de serviço dedicadas e sem permissões administrativas. Revise regularmente as permissões de cada processo ou daemon em produção e remova acessos que não são estritamente usados.

CVE-2026-18949HIGHOdh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resourcesEPSS 0.4%CVE-2026-89259CRITICALHugo before v0.165.0 Insufficient Permission Restriction via TailwindCSSEPSS 0.4%CVE-2025-13506HIGHImproper Authorization in Nebim Neyir's Nebim V3 ERPEPSS 0.4%CVE-2025-1137HIGHIBM Storage Scale command injectionEPSS 0.4%CVE-2025-67510CRITICALMySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)EPSS 0.4%CVE-2025-62503MEDIUMApache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)EPSS 0.4%CVE-2025-59481HIGHBIG-IP iControl REST and tmsh vulnerabilityEPSS 0.4%CVE-2025-61958HIGHBIG-IP TMSH vulnerabilityEPSS 0.4%CVE-2022-41950MEDIUMPrivilege Escalation Vulnerability by wrong chmod paramEPSS 0.4%CVE-2021-3101HIGHHotdog Container EscapeEPSS 0.4%CVE-2022-0071HIGHHotdog Container EscapeEPSS 0.4%CVE-2026-76018HIGHPrivilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentiallEPSS 0.4%CVE-2023-50015HIGHAn issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect acEPSS 0.4%CVE-2025-33109HIGHIBM i privilege escalationEPSS 0.4%CVE-2021-0223HIGHJunos OS: telnetd.real Local Privilege Escalation vulnerabilities in SUID binariesEPSS 0.4%CVE-2018-25078HIGHman-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is exeEPSS 0.4%CVE-2022-0070HIGHLog4j hot patch package privilege escalationEPSS 0.4%CVE-2021-1118HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to execute privileged oEPSS 0.4%CVE-2024-47903MEDIUMA vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All veEPSS 0.4%CVE-2026-72654MEDIUMExecution with Unnecessary Privileges in Kibana Leading to Information DisclosureEPSS 0.4%