Weaknesses of type CWE-284

7,074 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2022-23768HIGHNeo Information Sys. NIS-HAP11AC remote access and manipulation vulnerabilityEPSS 1.0%CVE-2017-7497MEDIUMThe dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability toEPSS 1.0%CVE-2024-13108MEDIUMD-Link DIR-816 A2 form2NetSniper.cgi access controlEPSS 1.0%CVE-2018-0119—A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, remote attacker to iEPSS 1.0%CVE-2019-11784MEDIUMImproper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remotEPSS 1.0%CVE-2019-11783MEDIUMImproper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows reEPSS 1.0%CVE-2022-38184HIGHThere is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1EPSS 1.0%CVE-2021-24318—Listeo < 1.6.11 - Multiple Authenticated IDOR VulnerabilitiesEPSS 1.0%CVE-2025-25968MEDIUMDDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitEPSS 1.0%CVE-2019-11895MEDIUMImproper access control in the JSON-RPC interface of the Bosch Smart Home Controller (SHC)EPSS 1.0%CVE-2019-15956HIGHCisco Web Security Appliance Unauthorized Device Reset VulnerabilityEPSS 1.0%CVE-2023-28300HIGHAzure Service Connector Security Feature Bypass VulnerabilityEPSS 1.0%CVE-2023-21751MEDIUMAzure DevOps Server Spoofing VulnerabilityEPSS 1.0%CVE-2025-30693MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0EPSS 1.0%CVE-2026-50006CRITICALAnyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server ModeEPSS 1.0%CVE-2019-0036HIGHJunos OS: Firewall filter terms named "internal-1" and "internal-2" being ignoredEPSS 1.0%CVE-2020-36721MEDIUMEpsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/DeactivationEPSS 1.0%CVE-2019-6144—This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP andEPSS 1.0%CVE-2021-36775HIGHDeleting PRTBs associated to a group doesn't cause deletion of corresponding RoleBindingsEPSS 1.0%CVE-2022-26313—A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations oEPSS 1.0%