Weaknesses of type CWE-284

7,165 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2025-54786MEDIUMSuiteCRM: Legacy iCal service allows unauthenticated access to meeting dataEPSS 0.3%CVE-2026-13864HIGHInsufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a maliEPSS 0.3%CVE-2025-65594HIGHOpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform EPSS 0.3%CVE-2025-15084LOWyoulaitech youlai-mall Order Payment OrderController.java orderService.payOrder access controlEPSS 0.3%CVE-2026-60533HIGHVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported vEPSS 0.3%CVE-2025-63409HIGHPrivilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator onEPSS 0.3%CVE-2025-63664HIGHIncorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackersEPSS 0.3%CVE-2025-65239MEDIUMIncorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers EPSS 0.3%CVE-2026-14848MEDIUMPaid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkoutEPSS 0.3%CVE-2025-57212HIGHIncorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a craEPSS 0.3%CVE-2025-57213HIGHIncorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via aEPSS 0.3%CVE-2025-57210HIGHIncorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspEPSS 0.3%CVE-2026-18466MEDIUMWP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option CreationEPSS 0.3%CVE-2025-63663HIGHIncorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to accEPSS 0.3%CVE-2022-26389HIGHImproper Access Control Vulnerability in ELI Electrocardiograph DevicesEPSS 0.3%CVE-2026-3932MEDIUMInsufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation resEPSS 0.3%CVE-2023-50159HIGHIn ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executeEPSS 0.3%CVE-2026-17824MEDIUMInsufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin polEPSS 0.3%CVE-2025-63214MEDIUMAn issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauthorized attackers to EPSS 0.3%CVE-2026-20909MEDIUMGitea tracked-time list endpoint has insufficient permission checksEPSS 0.3%