Weaknesses of type CWE-284

7,071 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2024-38202HIGHWindows Update Stack Elevation of Privilege VulnerabilityEPSS 1.7%CVE-2019-10962—BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway WEPSS 1.7%CVE-2018-15459MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilityEPSS 1.7%CVE-2022-37393—Zimbra zmslapd arbitrary module loadEPSS 1.7%CVE-2019-6520—Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuEPSS 1.7%CVE-2019-3567—In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder EPSS 1.7%CVE-2025-33056HIGHWindows Local Security Authority (LSA) Denial of Service VulnerabilityEPSS 1.7%CVE-2022-39399LOWVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versionsEPSS 1.6%CVE-2025-4751MEDIUMD-Link DI-7003GV2 index.data information disclosureEPSS 1.6%CVE-2020-9668HIGHAGSService program mishandling symbolic linksEPSS 1.6%CVE-2025-24989HIGHMicrosoft Power Pages Elevation of Privilege VulnerabilityEPSS 1.6%KEVCVE-2021-24583—Timetable and Event Schedule by MotoPress < 2.4.2 - Unauthorised Event TimeSlot DeletionEPSS 1.6%CVE-2024-49068HIGHMicrosoft SharePoint Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2026-21627CRITICALExtension - tassos.gr - SQL injection and Unauthenticated File Read in Novarain/Tassos Framework v4.10.14 – v6.0.37 for JoomlaEPSS 1.6%CVE-2014-2365—Advantech WebAccess Improper Access ControlEPSS 1.6%CVE-2019-1686MEDIUMCisco ASR 9000 Series Aggregation Services Routers ACL Bypass VulnerabilityEPSS 1.6%CVE-2026-24302HIGHAzure Arc Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2022-34259MEDIUMAdobe Commerce Improper Access Control Security feature bypassEPSS 1.6%CVE-2026-16330MEDIUMD-Link DNS-320 uploadify.php unrestricted uploadEPSS 1.6%CVE-2026-16327MEDIUMD-Link DNS-320 upload.php unrestricted uploadEPSS 1.6%