Weaknesses of type CWE-284

7,073 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2019-10200—A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedulEPSS 1.3%CVE-2023-1834CRITICALRockwell Automation Kinetix 5500 Vulnerable to Open Port ExploitationEPSS 1.3%CVE-2025-2553MEDIUMD-Link DIR-618/DIR-605L formVirtualServ access controlEPSS 1.3%CVE-2025-30433CRITICALThis issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15EPSS 1.2%CVE-2024-45489CRITICALArc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (beEPSS 1.2%CVE-2023-36722MEDIUMActive Directory Domain Services Information Disclosure VulnerabilityEPSS 1.2%CVE-2021-24197—wpDataTables < 3.4.2 - Improper Access Control leading to Table Permission TakeoverEPSS 1.2%CVE-2020-13675—Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, whEPSS 1.2%CVE-2024-43600HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2019-10964HIGHMedtronic MiniMed 508 and Paradigm Series Insulin Pumps Improper Access ControlEPSS 1.2%CVE-2020-14312—A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat EnterpriseEPSS 1.2%CVE-2021-40404MEDIUMAn authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-EPSS 1.2%CVE-2022-1553HIGHLeaking password protected articles content due to improper access control in publify/publifyEPSS 1.2%CVE-2021-1389MEDIUMCisco IOS XR and Cisco NX-OS Software IPv6 Access Control List Bypass VulnerabilityEPSS 1.2%CVE-2025-58751LOWVite middleware may serve files starting with the same name with the public directoryEPSS 1.2%CVE-2022-0133MEDIUMImproper Access Control in chocobozzz/peertubeEPSS 1.2%CVE-2022-0203HIGHImproper Access Control in crater-invoice/craterEPSS 1.2%CVE-2023-32632HIGHA command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted EPSS 1.2%CVE-2026-5786HIGHAn Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacEPSS 1.2%CVE-2026-9614HIGHAn Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain aEPSS 1.2%