Weaknesses of type CWE-284

7,169 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2025-46308MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. AnEPSS 0.2%CVE-2023-21438LOWImproper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.EPSS 0.2%CVE-2026-74929MEDIUMWP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOREPSS 0.2%CVE-2024-32045MEDIUMPlaybook run link to private channel grants channel accessEPSS 0.2%CVE-2026-9522MEDIUMImproper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user withouEPSS 0.2%CVE-2026-23522LOWLobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File DeletionEPSS 0.2%CVE-2026-87959MEDIUMWPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings UpdateEPSS 0.2%CVE-2026-13703MEDIUMSEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule DisclosureEPSS 0.2%CVE-2022-21813MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or prEPSS 0.2%CVE-2021-32002MEDIUMSiteManager troubleshooter allows access without authentication from local networkEPSS 0.2%CVE-2026-62529LOWVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.2%CVE-2025-9795MEDIUMxujeff tianti 天梯 UploadController.java ajaxUploadFile unrestricted uploadEPSS 0.2%CVE-2026-22605MEDIUMOpenProject is Vulnerable to Insecure Direct Object Reference in MeetingsEPSS 0.2%CVE-2026-11549MEDIUMMultiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.EPSS 0.2%CVE-2026-14926MEDIUMFluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOREPSS 0.2%CVE-2021-25405—An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to aEPSS 0.2%CVE-2025-14338HIGHPolkit authentication dis isabled by default in inputplumberEPSS 0.2%CVE-2022-33706—Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using SEPSS 0.2%CVE-2026-34294MEDIUMVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). The suEPSS 0.2%CVE-2023-21985HIGHVulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. EaEPSS 0.2%