Falhas do tipo CWE-266

1.170 resultados

Atribuição incorreta de privilégios

A aplicação concede permissões ou privilégios a usuários ou processos sem validar adequadamente se essa concessão é apropriada. Isso permite que um atacante escale privilégios, acesse recursos restritos ou execute operações que não deveria estar autorizado a fazer.

Exemplo

Um sistema de backup automático roda com permissões de root para acessar todos os arquivos, mas a interface de administração permite que qualquer usuário autenticado (até nível guest) configure quais diretórios fazer backup — criando a possibilidade de exfiltração de dados sensíveis através de um privilégio excessivamente amplo.

Como mitigar

Aplique princípio do menor privilégio: execute processos e serviços com o mínimo de permissão necessária; valide explicitamente cada mudança de contexto de segurança (ownership, grupos, capabilities) e auditore quem fez a concessão; use controle de acesso baseado em papéis (RBAC) com definições claras de qual papel pode executar qual operação.

CVE-2026-53862LOWOpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope WideningEPSS 0.1%CVE-2026-49413HIGHFlaw in Linuxulator execution of setugid binariesEPSS 0.1%CVE-2025-42992MEDIUMMultiple Privilege Escalation Vulnerabilities in SAPCAREPSS 0.1%CVE-2026-22078HIGHO+ Connect's lack of authentication for IPC channels led to a local privilege escalation vulnerability.EPSS 0.1%CVE-2025-58322HIGHNAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrarEPSS 0.1%CVE-2024-0085MEDIUMCVEEPSS 0.1%CVE-2025-48911HIGHVulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect EPSS 0.1%CVE-2024-31315MEDIUMIn multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notificatEPSS 0.1%CVE-2025-36007HIGHIBM QRadar SIEM incorrect privilege assignmentEPSS 0.1%CVE-2025-68420HIGHPrivilege Escalation in Comarch ERP OptimaEPSS 0.1%CVE-2025-36613LOWSupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect PriEPSS 0.1%CVE-2025-38738MEDIUMSupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in theEPSS 0.1%CVE-2026-12217HIGHDVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges managementEPSS 0.1%CVE-2024-32009HIGHA vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a loEPSS 0.1%CVE-2025-36612MEDIUMSupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attEPSS 0.1%CVE-2026-12201MEDIUMIObit Malware Fighter DLL permissionEPSS 0.1%CVE-2025-43914HIGHDell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release versionEPSS 0.1%CVE-2025-26425MEDIUMIn multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This couEPSS 0.1%CVE-2026-20110MEDIUMA vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) conditioEPSS 0.1%CVE-2023-21269—In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL byEPSS 0.1%