Weaknesses of type CWE-284

7,074 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2019-10175MEDIUMA flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determEPSS 1.0%CVE-2026-54629HIGHAnyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server ModeEPSS 1.0%CVE-2020-10278MEDIUMRVD#2561: Unprotected BIOS allows user to boot from live OS image.EPSS 1.0%CVE-2025-3783MEDIUMSourceCodester Web-based Pharmacy Product Management System add-product.php unrestricted uploadEPSS 1.0%CVE-2025-46628HIGHLack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attackeEPSS 1.0%CVE-2026-2056MEDIUMD-Link DIR-605L/DIR-619L DHCP Connection Status wan_connection_status.asp information disclosureEPSS 1.0%CVE-2026-2055MEDIUMD-Link DIR-605L/DIR-619L DHCP Client Information information disclosureEPSS 1.0%CVE-2023-44794—An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.EPSS 1.0%CVE-2026-2054MEDIUMD-Link DIR-605L/DIR-619L Wifi Setting information disclosureEPSS 1.0%CVE-2023-38945HIGHMultilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.0EPSS 1.0%CVE-2025-48817HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 1.0%CVE-2022-22190HIGHParagon Active Assurance Control Center: Information disclosure vulnerability in crafted URLEPSS 1.0%CVE-2022-24731MEDIUMPath traversal allows leaking out-of-bound files from Argo CD repo-serverEPSS 1.0%CVE-2024-23315HIGHA read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550EEPSS 1.0%CVE-2024-40786HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, mEPSS 1.0%CVE-2018-16466—Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acEPSS 1.0%CVE-2023-23923—Moodle: possible to set the preferred "start page" of other usersEPSS 1.0%CVE-2023-22250MEDIUMAdobe Commerce Improper Access Control Security feature bypassEPSS 1.0%CVE-2022-26317—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completeEPSS 1.0%CVE-2023-36644HIGHIncorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the EPSS 1.0%