Weaknesses of type CWE-284

7,070 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2025-27134HIGHPrivilege escalation in Joplin server via user patch endpointEPSS 2.1%CVE-2019-11780HIGHImproper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authentEPSS 2.1%CVE-2020-8207—Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the autoEPSS 2.1%CVE-2021-24219—All Thrive Themes and Plugins - Unauthenticated Option UpdateEPSS 2.1%CVE-2026-21262HIGHSQL Server Elevation of Privilege VulnerabilityEPSS 2.0%CVE-2021-35221MEDIUMImportAlert Improper Access Control Tampering VulnerabilityEPSS 2.0%CVE-2024-8805HIGHBlueZ HID over GATT Profile Improper Access Control Remote Code Execution VulnerabilityEPSS 2.0%CVE-2020-25654—An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communiEPSS 2.0%CVE-2021-36917MEDIUMWordPress Hide My WP premium plugin <= 6.2.3 - Unauthenticated Plugin Deactivation vulnerabilityEPSS 2.0%CVE-2021-4201CRITICALPre-authentication session hijackingEPSS 2.0%CVE-2024-29993HIGHAzure CycleCloud Elevation of Privilege VulnerabilityEPSS 2.0%CVE-2020-2506HIGHimproper access control vulnerability in HelpdeskEPSS 2.0%KEVCVE-2021-21083HIGHAdobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-serviceEPSS 2.0%CVE-2023-51644CRITICALAllegra SiteConfigAction Improper Access Control Remote Code Execution VulnerabilityEPSS 2.0%CVE-2020-5242HIGHopenHAB exec add-ons allow remote arbitrary command executionEPSS 2.0%CVE-2017-9626—Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based apEPSS 1.9%CVE-2022-21182HIGHA privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A speciaEPSS 1.9%CVE-2019-1763HIGHCisco IP Phone 8800 Series Authorization Bypass VulnerabilityEPSS 1.9%CVE-2025-23242HIGHNVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability mEPSS 1.9%CVE-2018-0343—A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to exEPSS 1.9%