Weaknesses of type CWE-284

7,122 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-1742MEDIUMEFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted uploadEPSS 0.4%CVE-2026-60422CRITICALVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). The supported version that is affEPSS 0.4%CVE-2026-71163CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-60719CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.4%CVE-2026-16547MEDIUMREST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download EndpointEPSS 0.4%CVE-2025-67645HIGHOpenEMR Vulnerable to Broken Access Control in Profile Edit EndpointEPSS 0.4%CVE-2026-2226MEDIUMDouPHP ZIP File file.php unrestricted uploadEPSS 0.4%CVE-2021-1228HIGHCisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized Access VulnerabilityEPSS 0.4%CVE-2025-6466MEDIUMageerle ruoyi-ai SseServiceImpl.java upload unrestricted uploadEPSS 0.4%CVE-2026-55119HIGHA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk AEPSS 0.4%CVE-2025-63822HIGHSirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parEPSS 0.4%CVE-2022-2995HIGHIncorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible dataEPSS 0.4%CVE-2026-34358HIGHCtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC BypassEPSS 0.4%CVE-2025-59333HIGH@executeautomation/database-server does not properly restrict access, bypassing a "read-only" modeEPSS 0.4%CVE-2026-9604MEDIUMJeecgBoot AiragModelController access controlEPSS 0.4%CVE-2026-18038MEDIUMnextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosureEPSS 0.4%CVE-2024-11484MEDIUMCode4Berry Decoration Management System User Image update_image.php access controlEPSS 0.4%CVE-2026-86285MEDIUMBookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm access controlEPSS 0.4%CVE-2022-45929HIGHNorthern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change EPSS 0.4%CVE-2025-55368HIGHIncorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modifyEPSS 0.4%