Weaknesses of type CWE-284

7,103 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-70854CRITICALVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.4%CVE-2021-24853—QR Redirector < 1.6 - Subscriber+ Arbitrary QR Redirect Response Status UpdateEPSS 0.4%CVE-2026-70976CRITICALVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.4%CVE-2026-60168CRITICALVulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions thatEPSS 0.4%CVE-2024-22074CRITICALDynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 throuEPSS 0.4%CVE-2026-71102CRITICALVulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21EPSS 0.4%CVE-2025-52101CRITICALlinjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the auEPSS 0.4%CVE-2023-2944MEDIUMImproper Access Control in openemr/openemrEPSS 0.4%CVE-2026-70981CRITICALVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.4%CVE-2026-46858CRITICALVulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). SuppEPSS 0.4%CVE-2026-76310CRITICALImproper Access Control through Embedded Report REST API Requests in Splunk EnterpriseEPSS 0.4%CVE-2024-21091MEDIUMVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The suEPSS 0.4%CVE-2026-76312CRITICALImproper Access Control through Embedded Reports in Splunk EnterpriseEPSS 0.4%CVE-2024-42514HIGHA vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to EPSS 0.4%CVE-2025-2278MEDIUMImproper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an aEPSS 0.4%CVE-2026-76311CRITICALImproper Access Control in Embedded Report Dispatch Archives in Splunk EnterpriseEPSS 0.4%CVE-2026-32254HIGHKube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoSEPSS 0.4%CVE-2024-36537HIGHInsecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service accoEPSS 0.4%CVE-2025-11508MEDIUMcode-projects Voting System voters_add.php unrestricted uploadEPSS 0.4%CVE-2025-50087MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.4%