Falhas do tipo CWE-280

169 resultados

Tratamento inadequado de permissões ou privilégios insuficientes

Ocorre quando o aplicativo não verifica corretamente se o usuário ou processo possui as permissões necessárias antes de executar uma ação sensível. O código assume que a operação foi autorizada sem validar o contexto de segurança, permitindo que usuários sem privilégio acessem recursos ou executem ações restritas.

Exemplo

Um painel administrativo que lista usuários sensíveis sem validar se o requisitante é administrador; qualquer usuário autenticado consegue acessar a rota /admin/users apenas porque a aplicação não verifica role ou permissão específica.

Como mitigar

Implementar controle de acesso explícito: valide permissões em cada operação sensível (authorization checks), use padrões como RBAC ou ABAC, e considere frameworks que forçam validação (ex: @RequireRole, middleware de permissões). Teste negativo: confirme que usuários sem privilégio são bloqueados.

CVE-2025-25179HIGHGPU DDK - Freelist GPU VA can be remapped to another reservation/PMR to trigger GPU arbitrary write to physical memoryEPSS 0.1%CVE-2026-64701HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious aEPSS 0.1%CVE-2024-51459HIGHIBM InfoSphere Server Information command executionEPSS 0.1%CVE-2022-22292HIGHUnprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.EPSS 0.1%CVE-2025-46584HIGHVulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation of this vulnerabilitEPSS 0.1%CVE-2024-8315MEDIUMImproper Handling of Insufficient Permissions or Privileges in B&R APROLEPSS 0.1%CVE-2026-21736MEDIUMGPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabledEPSS 0.1%CVE-2026-46054HIGHselinux: fix overlayfs mmap() and mprotect() access checksEPSS 0.1%CVE-2025-58770HIGHTCG2 TPM RT Not Locked IssueEPSS 0.1%CVE-2022-39912MEDIUMImproper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows EPSS 0.1%CVE-2026-84631HIGHThis issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root prEPSS 0.1%CVE-2025-31173HIGHMemory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect serEPSS 0.1%CVE-2025-31172HIGHMemory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect serEPSS 0.1%CVE-2026-86917HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahoeEPSS 0.1%CVE-2022-30725MEDIUMBroadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of BluetEPSS 0.1%CVE-2022-30724MEDIUMBroadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of BEPSS 0.1%CVE-2022-30723MEDIUMBroadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice functEPSS 0.1%CVE-2025-27521MEDIUMVulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affecEPSS 0.1%CVE-2025-45376HIGHDell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Privileges vulnerabiliEPSS 0.1%CVE-2026-59567HIGHLocal privilege escalationEPSS 0.1%