Weaknesses of type CWE-284

7,155 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2024-55402MEDIUM4C Strategies Exonaut before v22.4 was discovered to contain an access control issue.EPSS 0.3%CVE-2026-13328MEDIUMTLP Food Menu < 6.0.2 - Unauthenticated Reservation Status ModificationEPSS 0.3%CVE-2025-46175HIGHRuoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysEPSS 0.3%CVE-2025-64347HIGHApollo Router Improperly Enforces Renamed Access Control DirectivesEPSS 0.3%CVE-2026-77689MEDIUMAmelia Pro 9.0 - 9.8 - Unauthenticated Payment BypassEPSS 0.3%CVE-2026-84936MEDIUMEmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database BloatEPSS 0.3%CVE-2022-3027MEDIUMContec Health CMS8000EPSS 0.3%CVE-2026-85123MEDIUMEasy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login Form Type ConfusionEPSS 0.3%CVE-2026-87840MEDIUMTripzzy < 1.5.1 - Unauthenticated Booking Data TamperingEPSS 0.3%CVE-2026-21447HIGHBagisto has IDOR in Customer Order Reorder FunctionalityEPSS 0.3%CVE-2026-14322MEDIUMTimetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_methodEPSS 0.3%CVE-2026-14822MEDIUMEvent Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status ManipulationEPSS 0.3%CVE-2026-90976MEDIUMClean Login < 1.19 - Unauthenticated Account Creation with Registration DisabledEPSS 0.3%CVE-2025-46174HIGHRuoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUseEPSS 0.3%CVE-2026-90922MEDIUMPaid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency MismatchEPSS 0.3%CVE-2026-12966MEDIUMDirect Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX ActionsEPSS 0.3%CVE-2026-87252MEDIUMVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affectEPSS 0.3%CVE-2026-70780MEDIUMVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affEPSS 0.3%CVE-2026-79314HIGHA horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of oEPSS 0.3%CVE-2024-36257LOWLack of permission check when updating the profile picture of a remote user (shared channels enabled)EPSS 0.3%