Falhas do tipo CWE-280

155 resultados

Tratamento inadequado de permissões ou privilégios insuficientes

Ocorre quando o aplicativo não verifica corretamente se o usuário ou processo possui as permissões necessárias antes de executar uma ação sensível. O código assume que a operação foi autorizada sem validar o contexto de segurança, permitindo que usuários sem privilégio acessem recursos ou executem ações restritas.

Exemplo

Um painel administrativo que lista usuários sensíveis sem validar se o requisitante é administrador; qualquer usuário autenticado consegue acessar a rota /admin/users apenas porque a aplicação não verifica role ou permissão específica.

Como mitigar

Implementar controle de acesso explícito: valide permissões em cada operação sensível (authorization checks), use padrões como RBAC ou ABAC, e considere frameworks que forçam validação (ex: @RequireRole, middleware de permissões). Teste negativo: confirme que usuários sem privilégio são bloqueados.

CVE-2024-24116CRITICALAn issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.EPSS 28.2%CVE-2026-20817HIGHWindows Error Reporting Service Elevation of Privilege VulnerabilityEPSS 5.3%CVE-2020-8219An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a fulEPSS 2.2%CVE-2012-4550MEDIUMJboss enterprise application platform: jboss eap: jbeap: jboss enterprise application platform: unauthorized ejb access via authorization module bypassEPSS 2.1%CVE-2020-26195MEDIUMDell EMC PowerScale OneFS versions 8.1.2 – 9.1.0 contain an issue where the OneFS SMB directory auto-create may erroneously create a directoEPSS 1.8%CVE-2019-6570A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions,EPSS 1.4%CVE-2021-38312HIGHGutenberg Template Library & Redux Framework <= 4.2.11 Incorrect Authorization check to Arbitrary plugin installation and post deletionEPSS 1.3%CVE-2023-42931HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A proceEPSS 1.2%CVE-2019-13415Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to dataEPSS 1.0%CVE-2026-2340MEDIUMSamba: vfs_worm does not block directory modificationEPSS 0.9%CVE-2022-2193HIGHInsecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 autEPSS 0.9%CVE-2025-29826HIGHMicrosoft Dataverse Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2021-37175A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCEPSS 0.8%CVE-2020-29031HIGHInsecure Direct Object Reference in GateManager WebUI can cause privilege escalationEPSS 0.7%CVE-2023-22737MEDIUMwire-server vulnerable to unauthorized removal of Bots from ConversationsEPSS 0.7%CVE-2020-8117Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.EPSS 0.7%CVE-2024-29748HIGHthere is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional exeEPSS 0.7%KEVCVE-2022-4863HIGHImproper Handling of Insufficient Permissions or Privileges in usememos/memosEPSS 0.7%CVE-2024-25108CRITICALInsufficient authorization allowing elevated access to resources in pixelfedEPSS 0.7%CVE-2024-22078HIGHAn issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable EPSS 0.6%