Weaknesses of type CWE-284

7,095 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-2978MEDIUMFastApiAdmin Scheduled Task API controller.py upload_file_controller unrestricted uploadEPSS 0.5%CVE-2026-2977MEDIUMFastApiAdmin Scheduled Task API controller.py upload_controller unrestricted uploadEPSS 0.5%CVE-2026-84048MEDIUMJoomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2EPSS 0.5%CVE-2019-11894MEDIUMImproper access control in the backup mechanism of the Bosch Smart Home Controller (SHC)EPSS 0.5%CVE-2024-31805MEDIUMTOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter inEPSS 0.5%CVE-2023-43849MEDIUMIncorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users EPSS 0.5%CVE-2024-20927HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected areEPSS 0.5%CVE-2023-5916MEDIUMLissy93 Dashy Configuration save access controlEPSS 0.5%CVE-2022-28753HIGHZoom On-Premise Deployments: Improper Access Control VulnerabilityEPSS 0.5%CVE-2025-5178MEDIUMRealce Tecnologia Queue Ticket Kiosk Image File ajax.php unrestricted uploadEPSS 0.5%CVE-2026-2734MEDIUMAuthorization Bypass in SearchModelVersions in mlflow/mlflowEPSS 0.5%CVE-2024-4198LOWMattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authentiEPSS 0.5%CVE-2026-39310HIGHTrilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) BuildsEPSS 0.5%CVE-2024-4195LOWMattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authentEPSS 0.5%CVE-2020-36831MEDIUMNextScripts: Social Networks Auto-Poster <= 4.3.17 - Missing AuthorizationEPSS 0.5%CVE-2023-4183MEDIUMSourceCodester Inventory Management System Password edit_update.php access controlEPSS 0.5%CVE-2024-56330CRITICALSession VNC may be accessed by other sessions on the same host in stardustEPSS 0.5%CVE-2020-10145HIGHThe Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2EPSS 0.5%CVE-2026-47261HIGHWasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restrictionEPSS 0.5%CVE-2024-58330HIGHA missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analyticEPSS 0.5%