Weaknesses of type CWE-284

7,097 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2025-47794LOWNextcloud Server vulnerable to insecure temporary file creation, race with write access and permissionEPSS 0.5%CVE-2024-1476MEDIUMUnder Construction / Maintenance Mode from Acurax <= 2.6 - Information ExposureEPSS 0.5%CVE-2026-19244MEDIUMHKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access controlEPSS 0.5%CVE-2023-24546HIGHOn affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicioEPSS 0.5%CVE-2026-42222HIGHnginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeoverEPSS 0.5%CVE-2024-42048MEDIUMOpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated usersEPSS 0.5%CVE-2018-10905HIGHCloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with accEPSS 0.5%CVE-2022-47634HIGHM-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archiveEPSS 0.5%CVE-2026-1424MEDIUMPHPGurukul News Portal Profile Pic unrestricted uploadEPSS 0.5%CVE-2020-15279MEDIUMScanning exclusion paths disclosure in BEST for WindowsEPSS 0.5%CVE-2023-41570—MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.EPSS 0.5%CVE-2026-70849MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-72909HIGHERPNext: Broken Access Control on certain endpointsEPSS 0.5%CVE-2025-0341MEDIUMCampCodes Computer Laboratory Management System edit unrestricted uploadEPSS 0.5%CVE-2025-5130MEDIUMTmall Demo uploadProductImage unrestricted uploadEPSS 0.5%CVE-2026-34390MEDIUMMantisBT: Privilege Escalation from Manager to AdministratorEPSS 0.5%CVE-2022-44643MEDIUMAccess policy with access to all tenants and using label selectors has more accessEPSS 0.5%CVE-2026-28974HIGHThis issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS SequoiEPSS 0.5%CVE-2025-10847HIGHDX UIM Probe Improper ACL Handling RCEEPSS 0.5%CVE-2026-28876HIGHA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOSEPSS 0.5%