Falhas do tipo CWE-280

169 resultados

Tratamento inadequado de permissões ou privilégios insuficientes

Ocorre quando o aplicativo não verifica corretamente se o usuário ou processo possui as permissões necessárias antes de executar uma ação sensível. O código assume que a operação foi autorizada sem validar o contexto de segurança, permitindo que usuários sem privilégio acessem recursos ou executem ações restritas.

Exemplo

Um painel administrativo que lista usuários sensíveis sem validar se o requisitante é administrador; qualquer usuário autenticado consegue acessar a rota /admin/users apenas porque a aplicação não verifica role ou permissão específica.

Como mitigar

Implementar controle de acesso explícito: valide permissões em cada operação sensível (authorization checks), use padrões como RBAC ou ABAC, e considere frameworks que forçam validação (ex: @RequireRole, middleware de permissões). Teste negativo: confirme que usuários sem privilégio são bloqueados.

CVE-2024-47767MEDIUMTuleap lists trackers in the quick add actions of the backlog without any permissions checkEPSS 0.4%CVE-2025-6573CRITICALGPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/OverwriteEPSS 0.4%CVE-2023-2020MEDIUMUnauthorized scheduling of downtimes via REST APIEPSS 0.4%CVE-2025-8109HIGHGPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operationEPSS 0.4%CVE-2025-50170HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-46874CRITICALRuijie Reyee OS Improper Handling of Insufficient Permissions or PrivilegesEPSS 0.4%CVE-2025-49731LOWMicrosoft Teams Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-36112MEDIUMNautobot dynamic-group-members doesn't enforce permission restrictions on member objectsEPSS 0.4%CVE-2025-67848HIGHMoodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.EPSS 0.4%CVE-2022-34368MEDIUMDell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Permissions or PrivilegEPSS 0.4%CVE-2024-4468MEDIUMSalon booking system <= 9.9 - Missing AuthorizationEPSS 0.4%CVE-2024-0015HIGHIn convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. EPSS 0.4%CVE-2025-22256MEDIUMA improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1EPSS 0.4%CVE-2026-41566CRITICALApache Kvrocks: Improper permission for the APPLYBATCH commandEPSS 0.4%CVE-2023-52537HIGHVulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will afEPSS 0.4%CVE-2025-27024MEDIUMImproper File Access in Infinera G42EPSS 0.4%CVE-2024-46988MEDIUMTuleap does not properly check permissions for email notifications in trackersEPSS 0.4%CVE-2025-24029MEDIUMArtifact permissions are not verified in the Cross Tracker Search widget in TuleapEPSS 0.4%CVE-2024-30418HIGHVulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability wiEPSS 0.4%CVE-2026-73239MEDIUMApache Allura: Missing permission checks IDOREPSS 0.3%