Weaknesses of type CWE-284

7,111 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-32138HIGHNEXULEAN API Key LeakEPSS 0.4%CVE-2024-21589HIGHParagon Active Assurance Control Center: Information disclosure vulnerabilityEPSS 0.4%CVE-2024-1288MEDIUMSchema & Structured Data for WP & AMP <= 1.26 - Missing Authorization to reCaptcha Key ModificationEPSS 0.4%CVE-2026-77008MEDIUMHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Settings UpdateEPSS 0.4%CVE-2025-7898MEDIUMCodecanyon iDentSoft Account Setting Page updateSetting unrestricted uploadEPSS 0.4%CVE-2024-7154MEDIUMTOTOLINK A3700R Password Reset wizard.html access controlEPSS 0.4%CVE-2026-82629MEDIUMjeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted uploadEPSS 0.4%CVE-2024-37315LOWNextcloud Server's read-only users can restore old versionsEPSS 0.4%CVE-2024-43590HIGHVisual C++ Redistributable Installer Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-66916MEDIUMJoomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0EPSS 0.4%CVE-2025-45615CRITICALIncorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted requeEPSS 0.4%CVE-2023-39221MEDIUMImproper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via netEPSS 0.4%CVE-2024-49049HIGHVisual Studio Code Remote Extension Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-42354MEDIUMShopware vulnerable to Improper Access Control with ManyToMany associations in store-apiEPSS 0.4%CVE-2022-24930MEDIUMAn Improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware update MAR-2022 Release allows untrusted aEPSS 0.4%CVE-2025-45616CRITICALIncorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.EPSS 0.4%CVE-2026-22043MEDIUMRustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account MintingEPSS 0.4%CVE-2026-64793CRITICALJoomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensionsEPSS 0.4%CVE-2025-30127CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, thEPSS 0.4%CVE-2026-56335HIGHCapgo - Channel Configuration Mutation via Write-Scoped API KeysEPSS 0.4%