Weaknesses of type CWE-284

7,073 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2023-4546LOWByzoro Smart S85F Management Platform licence.php access controlEPSS 1.3%CVE-2026-24300CRITICALAzure Front Door Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2023-24320CRITICALAn access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.EPSS 1.3%CVE-2022-35689MEDIUMAdobe Commerce Improper Access Control Security feature bypassEPSS 1.3%CVE-2022-3065MEDIUMImproper Access Control in jgraph/drawioEPSS 1.3%CVE-2025-29804HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2026-44249HIGHNetty has an IPv6 Subnet Filter Bypass via Incorrect Comparator MaskingEPSS 1.3%CVE-2018-0436—Cisco Webex Teams Information Disclosure and Modification VulnerabilityEPSS 1.3%CVE-2020-10641—An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication.EPSS 1.3%CVE-2021-1243MEDIUMCisco IOS XR Software SNMP Management Plane Protection ACL Bypass VulnerabilityEPSS 1.3%CVE-2018-11456—A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device EPSS 1.3%CVE-2022-20859MEDIUMCisco Unified Communications Products Access Control VulnerabilityEPSS 1.3%CVE-2023-46501CRITICALAn issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin passEPSS 1.3%CVE-2020-14504MEDIUMThe web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attackeEPSS 1.3%CVE-2016-9368—An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform reEPSS 1.3%CVE-2021-32517HIGHQSAN Storage Manager - Improper Access ControlEPSS 1.3%CVE-2026-4201MEDIUMglowxq glowxq-oj SysFileController.java upload unrestricted uploadEPSS 1.3%CVE-2025-63353CRITICALA vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be preEPSS 1.3%CVE-2018-10612—In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryptiEPSS 1.3%CVE-2024-3765CRITICALXiongmai AHB7804R-MH-V2 Sofia Service access controlEPSS 1.3%