Falhas do tipo CWE-494

187 resultados

Elevação de privilégio

A aplicação não valida corretamente permissões ou contexto de segurança, permitindo que um usuário com privilégios baixos execute ações reservadas a administradores ou usuários com acesso mais elevado. É perigoso porque quebra o modelo de controle de acesso e expõe funcionalidades críticas.

Exemplo

Um usuário comum consegue acessar a API de administração porque o servidor valida apenas a presença de um token válido, ignorando o campo de 'role' contido nele; ou um programa SUID não revoga permissões root antes de executar código fornecido pelo usuário, permitindo leitura de arquivos sensíveis.

Como mitigar

Implemente verificação rigorosa de permissões em toda ação sensível (autorização não apenas autenticação), use listas de controle de acesso (ACL) explícitas, aplique princípio do menor privilégio e audite chamadas privilegiadas. Teste com usuários em papéis baixos para confirmar bloqueios.

CVE-2026-42249HIGHRemote Code Execution in Ollama via Update MechanismEPSS 0.6%CVE-2023-39474HIGHInductive Automation Ignition downloadLaunchClientJar Remote Code Execution VulnerabilityEPSS 0.6%CVE-2020-7873HIGHDownload of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary fEPSS 0.6%CVE-2019-3801HIGHJava Projects using HTTP to fetch dependenciesEPSS 0.6%CVE-2020-7874HIGHNEXACRO14 Runtime arbitrary file download and execution vulnerabilityEPSS 0.6%CVE-2023-23110HIGHAn exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware iEPSS 0.6%CVE-2018-14620MEDIUMThe OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could poEPSS 0.6%CVE-2020-22658CRITICALIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.5%CVE-2026-2999CRITICALChanging|IDExpert Windows Logon Agent - Remote Code ExecutionEPSS 0.5%CVE-2026-3000CRITICALChanging|IDExpert Windows Logon Agent - Remote Code ExecutionEPSS 0.5%CVE-2020-9751Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upEPSS 0.5%CVE-2019-10248Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependentEPSS 0.5%CVE-2024-30205HIGHIn Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.EPSS 0.5%CVE-2020-29032HIGHAdd integrity check of GateManager firmwareEPSS 0.5%CVE-2025-63215HIGHThe Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The uEPSS 0.5%CVE-2025-63220HIGHThe Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The upEPSS 0.5%CVE-2021-26639HIGHWISA Smart Wing CMS File Download VulnerabilityEPSS 0.5%CVE-2026-25961HIGHSumatraPDF Update MITM -> Arbitrary Code ExecutionEPSS 0.5%CVE-2025-56513CRITICALNiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of iEPSS 0.4%CVE-2025-11182HIGHFile Download in GTONE ChangeFlowEPSS 0.4%