Falhas do tipo CWE-266

1.170 resultados

Atribuição incorreta de privilégios

A aplicação concede permissões ou privilégios a usuários ou processos sem validar adequadamente se essa concessão é apropriada. Isso permite que um atacante escale privilégios, acesse recursos restritos ou execute operações que não deveria estar autorizado a fazer.

Exemplo

Um sistema de backup automático roda com permissões de root para acessar todos os arquivos, mas a interface de administração permite que qualquer usuário autenticado (até nível guest) configure quais diretórios fazer backup — criando a possibilidade de exfiltração de dados sensíveis através de um privilégio excessivamente amplo.

Como mitigar

Aplique princípio do menor privilégio: execute processos e serviços com o mínimo de permissão necessária; valide explicitamente cada mudança de contexto de segurança (ownership, grupos, capabilities) e auditore quem fez a concessão; use controle de acesso baseado em papéis (RBAC) com definições claras de qual papel pode executar qual operação.

CVE-2026-19190HIGHStableBit Scanner ScannerService Scanner.Service.exe permissionEPSS 0.2%CVE-2026-12782HIGHEaseUS Partition Master Kernel Driver EUEDKEPM.sys access controlEPSS 0.2%CVE-2026-12823MEDIUMBrowserbase Skills Autobrowse Trace Artifact default permissionEPSS 0.2%CVE-2026-12781HIGHEaseUS Partition Master Kernel Driver epmntdrv.sys access controlEPSS 0.2%CVE-2025-1078MEDIUMAppHouseKitchen AlDente Charge Limiter XPC Service com.apphousekitchen.aldente-pro.helper shouldAcceptNewConnection improper authorizationEPSS 0.2%CVE-2026-19192HIGHDeepCool DisplayService DeepCoolDisplayService.exe access controlEPSS 0.2%CVE-2026-82628CRITICALColorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges managementEPSS 0.2%CVE-2026-19191HIGHStableBit DrivePool DrivePoolService DrivePool.Service.exe permissionEPSS 0.2%CVE-2022-50927HIGHCyclades Serial Console Server 3.3.0 - Local Privilege EscalationEPSS 0.2%CVE-2026-82671MEDIUMIObit Unlocker IRP_MJ_DEVICE_CONTROL IObitUnlocker.sys ZwTerminateProcess privileges managementEPSS 0.2%CVE-2024-37134MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacEPSS 0.2%CVE-2024-46974HIGHGPU DDK - Arbitrary write of read-only dmabufEPSS 0.2%CVE-2024-39579MEDIUMDell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attEPSS 0.2%CVE-2026-67846HIGHBerkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issEPSS 0.2%CVE-2024-27275HIGHIBM i privilege escalationEPSS 0.2%CVE-2026-90493CRITICALTonec Internet Download Manager Kernel Driver idmwfp.sys access controlEPSS 0.2%CVE-2025-8757HIGHTRENDnet TV-IP110WN Embedded Boa Web Server boa.conf least privilege violationEPSS 0.2%CVE-2023-5080MEDIUMA privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identiEPSS 0.2%CVE-2025-0131HIGHGlobalProtect App: Incorrect Privilege Management Vulnerability in OPSWAT MetaDefender Endpoint Security SDKEPSS 0.2%CVE-2024-7480MEDIUMImproper access control in Avaya Aura System ManagerEPSS 0.2%