Falhas do tipo CWE-494

187 resultados

Elevação de privilégio

A aplicação não valida corretamente permissões ou contexto de segurança, permitindo que um usuário com privilégios baixos execute ações reservadas a administradores ou usuários com acesso mais elevado. É perigoso porque quebra o modelo de controle de acesso e expõe funcionalidades críticas.

Exemplo

Um usuário comum consegue acessar a API de administração porque o servidor valida apenas a presença de um token válido, ignorando o campo de 'role' contido nele; ou um programa SUID não revoga permissões root antes de executar código fornecido pelo usuário, permitindo leitura de arquivos sensíveis.

Como mitigar

Implemente verificação rigorosa de permissões em toda ação sensível (autorização não apenas autenticação), use listas de controle de acesso (ACL) explícitas, aplique princípio do menor privilégio e audite chamadas privilegiadas. Teste com usuários em papéis baixos para confirmar bloqueios.

CVE-2025-15575MEDIUMMissing Firmware Authenticity Checks in Solax Power Pocket WiFi modelsEPSS 0.1%CVE-2026-49450HIGHJoplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherNameEPSS 0.1%CVE-2025-55310HIGHAn issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replaEPSS 0.1%CVE-2023-22635MEDIUMA download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 allEPSS 0.1%CVE-2026-30603MEDIUMAn issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, aEPSS 0.1%CVE-2026-13433HIGHIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.1%CVE-2026-62654HIGHA vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key EPSS 0.1%CVE-2025-61228HIGHAn issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanismEPSS 0.1%CVE-2025-65855MEDIUMThe OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentiaEPSS 0.1%CVE-2025-52937LOWVulnerability in PointCloudLibrary PCLEPSS 0.1%CVE-2026-84664MEDIUMJenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowinEPSS 0.1%CVE-2026-84666MEDIUMJenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration thEPSS 0.1%CVE-2026-12259MEDIUMImproper Input Validation in nltk/nltkEPSS 0.1%CVE-2024-39819MEDIUMZoom Workplace Apps and SDK for Windows - Improper Privilege ManagementEPSS 0.1%CVE-2025-53696CRITICALiSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmEPSS 0.1%CVE-2026-7006HIGHSublime Text 4192/3207 Local Privilege Escalation via Update Staging MechanismEPSS 0.1%CVE-2025-47904MEDIUMUnsigned upgrade packageEPSS 0.1%CVE-2024-42183LOWHCL BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerabilityEPSS 0.1%CVE-2026-76241HIGHstigmem Plugin Signature Enforcement Bypass via ConfigurationEPSS 0.1%CVE-2026-80047HIGHHugging Face Transformers library writes remote code to disk prior to consent checkEPSS 0.1%