Weaknesses of type CWE-284

7,103 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2025-7538MEDIUMCampcodes Sales and Inventory System product_update.php unrestricted uploadEPSS 0.4%CVE-2025-7470MEDIUMCampcodes Sales and Inventory System product_add.php unrestricted uploadEPSS 0.4%CVE-2025-55373MEDIUMIncorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to escalate privilegesEPSS 0.4%CVE-2022-23994LOWAn Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted EPSS 0.4%CVE-2026-48034HIGHHULUMI-H5 bypass via decoy sibling resources targeting a different bucketEPSS 0.4%CVE-2025-6422MEDIUMCampcodes Online Recruitment Management System About Content Page ajax.php unrestricted uploadEPSS 0.4%CVE-2026-95624MEDIUMTauri framework v2 malicious downgrade via allow_downgrades from frontend codeEPSS 0.4%CVE-2024-1678MEDIUMSubway – Private Site Option <= 2.1.4 - Improper Access Control to Sensitive Information Exposure via REST APIEPSS 0.4%CVE-2026-43713MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS TaEPSS 0.4%CVE-2025-45422HIGHIncorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes EPSS 0.4%CVE-2026-21994CRITICALVulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: EPSS 0.4%CVE-2024-41251MEDIUMAn Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_sEPSS 0.4%CVE-2026-47164HIGHVaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP IdentityEPSS 0.4%CVE-2025-41737HIGHImproper access control via php endpointEPSS 0.4%CVE-2025-49707HIGHAzure Virtual Machines Spoofing VulnerabilityEPSS 0.4%CVE-2026-28862MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.5, macOS SonomEPSS 0.4%CVE-2025-9153MEDIUMitsourcecode Online Tour and Travel Management System travellers.php unrestricted uploadEPSS 0.4%CVE-2026-71102CRITICALVulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21EPSS 0.4%CVE-2025-52101CRITICALlinjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the auEPSS 0.4%CVE-2026-62638CRITICALVulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported EPSS 0.4%