Falhas do tipo CWE-280

168 resultados

Tratamento inadequado de permissões ou privilégios insuficientes

Ocorre quando o aplicativo não verifica corretamente se o usuário ou processo possui as permissões necessárias antes de executar uma ação sensível. O código assume que a operação foi autorizada sem validar o contexto de segurança, permitindo que usuários sem privilégio acessem recursos ou executem ações restritas.

Exemplo

Um painel administrativo que lista usuários sensíveis sem validar se o requisitante é administrador; qualquer usuário autenticado consegue acessar a rota /admin/users apenas porque a aplicação não verifica role ou permissão específica.

Como mitigar

Implementar controle de acesso explícito: valide permissões em cada operação sensível (authorization checks), use padrões como RBAC ou ABAC, e considere frameworks que forçam validação (ex: @RequireRole, middleware de permissões). Teste negativo: confirme que usuários sem privilégio são bloqueados.

CVE-2025-27024MEDIUMImproper File Access in Infinera G42EPSS 0.3%CVE-2019-17437HIGHPAN-OS: Custom-role users may escalate privilegesEPSS 0.3%CVE-2024-12430HIGHAn attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 veEPSS 0.3%CVE-2025-22129MEDIUMInitial effort field does not respect field permissions in the Taskboard REST card representation in TuleapEPSS 0.3%CVE-2024-46988MEDIUMTuleap does not properly check permissions for email notifications in trackersEPSS 0.3%CVE-2024-35228MEDIUMImproper Handling of Insufficient Permissions in WagtailEPSS 0.3%CVE-2025-59040MEDIUMTuleap backlog item representations do not verify the permissions of the child trackersEPSS 0.3%CVE-2024-6697MEDIUMHitachi Vantara Pentaho Business Analytics Server - Improper Handling of Insufficient Permissions or PrivilegesEPSS 0.3%CVE-2024-43702HIGHGPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pagesEPSS 0.3%CVE-2023-39249MEDIUM Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated noEPSS 0.3%CVE-2026-3190MEDIUMKeycloak: keycloak: information disclosure via improper role enforcement in uma 2.0 protection apiEPSS 0.3%CVE-2025-46740HIGHImproper Handling of Insufficient PermissionsEPSS 0.3%CVE-2025-58457MEDIUMApache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore CommandsEPSS 0.3%CVE-2020-3427MEDIUMDuo Authentication for Windows Logon and RDP Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-18860HIGHVelociraptor incorrect Org deletion permissions checkEPSS 0.3%CVE-2025-62509HIGHFileRise improper ownership/permission validation allowed cross-tenant file operationsEPSS 0.3%CVE-2025-62510HIGHFileRise insecure folder visibility via name-based mapping and incomplete ACL checksEPSS 0.3%CVE-2024-6302HIGHImproper Handling of Insufficient Permissions or Privileges in ConduitEPSS 0.3%CVE-2026-69907HIGHWindows Enterprise App Management Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-4692LOWMultiple missing permission checksEPSS 0.3%