Weaknesses of type CWE-284

7,168 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-101146MEDIUMEleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosureEPSS 0.3%CVE-2024-27803LOWA permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical accesEPSS 0.3%CVE-2026-70853LOWVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.3%CVE-2026-46696LOWOctober CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder CallsEPSS 0.3%CVE-2025-7487MEDIUMJoeyBling SpringBoot_MyBatisPlus upload SysFileController unrestricted uploadEPSS 0.3%CVE-2025-24236MEDIUMAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app mEPSS 0.3%CVE-2026-86858HIGHUnauthenticated Privilege Escalation via GraphQL in ServiceNow AI PlatformEPSS 0.3%CVE-2026-84200CRITICALKyverno before v1.13.0 Policy Bypass via Multiple ExceptionsEPSS 0.3%CVE-2026-2205MEDIUMWeKan Meteor Publication cards.js CardPubSubBleed information disclosureEPSS 0.3%CVE-2026-56608LOWHCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).EPSS 0.3%CVE-2026-101891CRITICALWatchGuard AP Improper Access Control in API Service Allows Unauthenticated AccessEPSS 0.3%CVE-2026-34082MEDIUMDify has IDOR in deleting someone else's chat conversationEPSS 0.3%CVE-2026-34324MEDIUMVulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: App Server). Supported versions thEPSS 0.3%CVE-2026-17023MEDIUMSalon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth CallbackEPSS 0.3%CVE-2026-73886HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2025-61749LOWVulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitaEPSS 0.3%CVE-2026-73893MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-62460MEDIUMVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.3%CVE-2026-46810MEDIUMVulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported versions that are aEPSS 0.3%CVE-2026-73876HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%