Weaknesses of type CWE-284

7,169 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-62486MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%CVE-2024-39797MEDIUMImproper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated usEPSS 0.2%CVE-2026-97332MEDIUMUser Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)EPSS 0.2%CVE-2023-23573MEDIUMImproper access control in the Intel(R) Unite(R) android application before Release 17 may allow a privileged user to potentially enable infEPSS 0.2%CVE-2026-60163HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions EPSS 0.2%CVE-2025-43418MEDIUMThis issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 anEPSS 0.2%CVE-2026-22014LOWVulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versionEPSS 0.2%CVE-2024-36438HIGHeLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to cEPSS 0.2%CVE-2026-12990HIGHMultiple vulnerabilities in Ghost Robotics' Vision 60EPSS 0.2%CVE-2025-44525MEDIUMTexas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient permission checks on criEPSS 0.2%CVE-2026-50132HIGHBudibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account Impersonation in BudibaseEPSS 0.2%CVE-2025-27238LOWAPI hostprototype.get lists data to users with insufficient authorization.EPSS 0.2%CVE-2025-11634LOWTomofun Furbo 360/Furbo Mini UART information disclosureEPSS 0.2%CVE-2025-69284MEDIUMIn plane.io, a Guest User to a Workspace can still be able to see list of membersEPSS 0.2%CVE-2024-24902MEDIUMDell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentEPSS 0.2%CVE-2023-42540MEDIUMImproper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via impEPSS 0.2%CVE-2025-65096MEDIUMRomM Insecure Direct Object Reference (IDOR) Allows Unauthorized Access to Private CollectionsEPSS 0.2%CVE-2022-36441HIGHAn issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use seveEPSS 0.2%CVE-2026-13144LOWWP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment ResetEPSS 0.2%CVE-2025-43332MEDIUMA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.EPSS 0.2%