Weaknesses of type CWE-284

7,145 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-56050MEDIUMWordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-8859MEDIUMcode-projects eBlog Site File Upload save-slider.php unrestricted uploadEPSS 0.3%CVE-2026-60188MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.3%CVE-2026-0844HIGHSimple User Registration <= 6.7 - Authenticated (Subscriber+) Privilege Escalation via profile_save_fieldEPSS 0.3%CVE-2026-13897HIGHInsufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalatEPSS 0.3%CVE-2024-13693MEDIUMEnfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.phpEPSS 0.3%CVE-2026-13171HIGHEventin < 4.1.20 - Unauthenticated Account Creation via Waiting List EndpointEPSS 0.3%CVE-2025-4281MEDIUMShenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclosureEPSS 0.3%CVE-2024-4263MEDIUMImproper Access Control in mlflow/mlflowEPSS 0.3%CVE-2026-41270HIGHFlowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function SandboxEPSS 0.3%CVE-2025-9841MEDIUMcode-projects Mobile Shop Management System AddNewProduct.php unrestricted uploadEPSS 0.3%CVE-2026-60189MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.3%CVE-2023-3096MEDIUMKylinSoft kylin-software-properties changedSource access controlEPSS 0.3%CVE-2026-14829HIGHCheckimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded SecretEPSS 0.3%CVE-2026-46936MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected areEPSS 0.3%CVE-2025-66911MEDIUMTurms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. TEPSS 0.3%CVE-2022-42862MEDIUMThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may beEPSS 0.3%CVE-2022-42859MEDIUMMultiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOSEPSS 0.3%CVE-2026-70691HIGHVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication InterfaceEPSS 0.3%CVE-2023-47294HIGHAn issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete userEPSS 0.3%