Weaknesses of type CWE-284

7,168 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-71077MEDIUMVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that isEPSS 0.3%CVE-2026-77695MEDIUMWoo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and ManipulationEPSS 0.3%CVE-2026-77010MEDIUMHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Join URL Disclosure and Class Access Code BypassEPSS 0.3%CVE-2024-44303HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify proteEPSS 0.3%CVE-2026-75793MEDIUMSureCart < 4.7.0 - Unauthenticated Account Creation with Automatic LoginEPSS 0.3%CVE-2026-86812MEDIUMWPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST APIEPSS 0.3%CVE-2026-12688MEDIUMProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN ForgeryEPSS 0.3%CVE-2026-14834MEDIUMMailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAXEPSS 0.3%CVE-2025-0744HIGHImproper Access Control vulnerability in EmbedAIEPSS 0.3%CVE-2026-34312LOWVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulEPSS 0.3%CVE-2026-42862HIGHFlowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource ReassignmentEPSS 0.3%CVE-2026-14315MEDIUMPixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event SubmissionEPSS 0.3%CVE-2025-50897MEDIUMA vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translationsEPSS 0.3%CVE-2024-5270MEDIUMSAML to email switch possible when email signin is disabledEPSS 0.3%CVE-2026-83085HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.3%CVE-2026-101146MEDIUMEleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosureEPSS 0.3%CVE-2024-30148MEDIUMHCL Leap is affected by improper access controlEPSS 0.3%CVE-2026-20322CRITICALCisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access ControlEPSS 0.3%CVE-2024-0104MEDIUMNVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause impropeEPSS 0.3%CVE-2026-48956MEDIUMJoomla! Core - [20260710] - Incorrect Access Control in com_modulesEPSS 0.3%