Weaknesses of type CWE-284

7,169 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2021-22907—An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions pEPSS 0.2%CVE-2026-3939MEDIUMInsufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions vEPSS 0.2%CVE-2026-47032LOWVulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.EPSS 0.2%CVE-2025-55626MEDIUMAn Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662EPSS 0.2%CVE-2025-50434MEDIUMA security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is related to incorrecEPSS 0.2%CVE-2025-57219MEDIUMIncorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate priviEPSS 0.2%CVE-2024-57336MEDIUMIncorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to oEPSS 0.2%CVE-2020-7253MEDIUMImproper access control vulnerability in McAfee AgentEPSS 0.2%CVE-2022-42327HIGHx86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and wriEPSS 0.2%CVE-2026-87262HIGHVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication InterfaceEPSS 0.2%CVE-2025-43495MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be aEPSS 0.2%CVE-2026-50325HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2023-44283HIGH In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concEPSS 0.2%CVE-2025-36351MEDIUMIBM License Metric Tool bypass securityEPSS 0.2%CVE-2022-27635HIGHImproper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enablEPSS 0.2%CVE-2021-34864HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.2%CVE-2026-50297HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2024-21805HIGHImproper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If thiEPSS 0.2%CVE-2026-49805HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-62461LOWVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.2%