Falhas do tipo CWE-669

76 resultados

Transferência incorreta de recursos entre contextos de segurança

Ocorre quando um recurso (arquivo, memória, conexão, credencial) é movido ou compartilhado entre contextos de segurança diferentes (ex: processo privilegiado para não-privilegiado, zona confiável para não-confiável) sem validação ou proteção adequada. O recurso fica acessível a quem não deveria, ou perde suas garantias de segurança na transição.

Exemplo

Um aplicativo web salva dados sensíveis do usuário em /tmp com permissões 0644 (legível por todos), e outro processo de menor privilégio consegue ler. Ou um serviço transmite um file descriptor aberto para um cliente não autenticado, que ganha acesso ao arquivo sem passar por controles de autorização.

Como mitigar

Valide e controle explicitamente cada transferência de recurso: revise quem pode acessar o quê após a transferência, use permissões restritivas (0600), criptografe dados sensíveis em trânsito, e aplique re-autenticação ou re-autorização quando recursos cruzam limites de segurança.

CVE-2026-44599LOWTor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.EPSS 0.3%CVE-2026-40552MEDIUMRemote Code Execution in mpGabinetEPSS 0.3%CVE-2026-75010MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authenticationEPSS 0.3%CVE-2026-44917MEDIUMOpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pEPSS 0.3%CVE-2025-62775HIGHMercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.EPSS 0.3%CVE-2026-46448MEDIUMIn OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.EPSS 0.3%CVE-2026-12068HIGHAvira Password Manager credential disclosure via cross-origin autofill in FirefoxEPSS 0.3%CVE-2026-46447MEDIUMOpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_infoEPSS 0.3%CVE-2026-87724MEDIUMTor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial EPSS 0.3%CVE-2025-46553LOW@misskey-dev/summaly Redirect Filter BypassEPSS 0.2%CVE-2024-31573MEDIUMXMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transEPSS 0.2%CVE-2026-33265MEDIUMIn LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.EPSS 0.2%CVE-2025-62292MEDIUMIn SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/useEPSS 0.2%CVE-2026-25832LOWIn Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.EPSS 0.2%CVE-2025-59691LOWPureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as WiEPSS 0.2%CVE-2025-59692LOWPureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and applyEPSS 0.2%CVE-2025-26698LOWIncorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downlEPSS 0.2%CVE-2023-37253LOWAn issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the APEPSS 0.2%CVE-2023-37252LOWAn issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.EPSS 0.2%CVE-2026-73574LOWIn Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper vEPSS 0.2%