Falhas do tipo CWE-266

1.169 resultados

Atribuição incorreta de privilégios

A aplicação concede permissões ou privilégios a usuários ou processos sem validar adequadamente se essa concessão é apropriada. Isso permite que um atacante escale privilégios, acesse recursos restritos ou execute operações que não deveria estar autorizado a fazer.

Exemplo

Um sistema de backup automático roda com permissões de root para acessar todos os arquivos, mas a interface de administração permite que qualquer usuário autenticado (até nível guest) configure quais diretórios fazer backup — criando a possibilidade de exfiltração de dados sensíveis através de um privilégio excessivamente amplo.

Como mitigar

Aplique princípio do menor privilégio: execute processos e serviços com o mínimo de permissão necessária; valide explicitamente cada mudança de contexto de segurança (ownership, grupos, capabilities) e auditore quem fez a concessão; use controle de acesso baseado em papéis (RBAC) com definições claras de qual papel pode executar qual operação.

CVE-2025-10038MEDIUMBinary MLM Plan <= 3.0 - Unauthenticated Limited Privilege EscalationEPSS 0.3%CVE-2024-48941CRITICALThe Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interactiEPSS 0.3%CVE-2025-10291MEDIUMlinlinjava litemall cancel WxAftersaleController improper authorizationEPSS 0.3%CVE-2025-4692MEDIUMABUP IoT Cloud Platform Incorrect Privilege AssignmentEPSS 0.3%CVE-2019-19349An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped inEPSS 0.3%CVE-2025-8791MEDIUMLitmusChaos Litmus list_projects improper authorizationEPSS 0.3%CVE-2026-2107MEDIUMyeqifu warehouse Log Info LoginfoController.java batchDeleteLoginfo improper authorizationEPSS 0.3%CVE-2025-0628HIGHImproper Authorization in BerriAI/litellmEPSS 0.3%CVE-2025-44655CRITICALIn TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorEPSS 0.3%CVE-2026-2106MEDIUMyeqifu warehouse Notice Management NoticeController.java batchDeleteNotice improper authorizationEPSS 0.3%CVE-2026-3761MEDIUMSourceCodester Client Database Management System Endpoint superadmin_user_delete.php improper authorizationEPSS 0.3%CVE-2026-2010LOWSanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorizationEPSS 0.3%CVE-2026-1962MEDIUMWeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access controlEPSS 0.3%CVE-2026-1963MEDIUMWeKan Attachment Storage attachments.js MoveStorageBleed access controlEPSS 0.3%CVE-2026-13511LOWVoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorizationEPSS 0.3%CVE-2025-8839MEDIUMjshERP Endpoint addUser improper authorizationEPSS 0.3%CVE-2026-6201MEDIUMCodeAstro Online Job Portal Delete Job Posting job-delete.php access controlEPSS 0.3%CVE-2026-6564MEDIUMEMQ EMQX Enterprise Session Handling improper authorizationEPSS 0.3%CVE-2024-50701MEDIUMTeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a userEPSS 0.3%CVE-2026-42731CRITICALWordPress miniorange otp verification plugin <= 5.4.9 - Privilege Escalation vulnerabilityEPSS 0.3%