Weaknesses of type CWE-284

7,169 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2024-47975HIGHImproper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized EPSS 0.2%CVE-2025-53112MEDIUMGLPI's incomprehensive permission checks can lead to data removal from allowed usersEPSS 0.2%CVE-2026-90917MEDIUMJoomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3EPSS 0.2%CVE-2025-43396MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A sandEPSS 0.2%CVE-2025-43477MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.2, macOS SonomEPSS 0.2%CVE-2026-36180MEDIUMA lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modifyEPSS 0.2%CVE-2026-2311MEDIUMIBM i is affected by a privilege escalation vulnerability in Web Administration GUI []EPSS 0.2%CVE-2022-37341HIGHImproper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privilegEPSS 0.2%CVE-2023-29164MEDIUMImproper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP,EPSS 0.2%CVE-2022-36443HIGHAn issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wirEPSS 0.2%CVE-2022-23829HIGHA potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native SystEPSS 0.2%CVE-2025-43371HIGHThis issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.EPSS 0.2%CVE-2021-25431—Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows unEPSS 0.2%CVE-2023-0012MEDIUMLocal Privilege Escalation in SAP Host Agent (Windows)EPSS 0.2%CVE-2025-31270MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access protecteEPSS 0.2%CVE-2025-43498MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, EPSS 0.2%CVE-2023-44289HIGH Dell Command | Configure versions prior to 4.11.0, contain an improper access control vulnerability. A local malicious standard user could EPSS 0.2%CVE-2026-64791HIGHJoomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension ManagerEPSS 0.2%CVE-2023-40070HIGHImproper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable EPSS 0.2%CVE-2023-44290HIGH Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could pEPSS 0.2%