Weaknesses of type CWE-284

7,169 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2023-3039HIGH SD ROM Utility, versions prior to 1.0.2.0 contain an Improper Access Control vulnerability. A low-privileged malicious user may potentiallyEPSS 0.2%CVE-2022-41621LOWImproper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable EPSS 0.2%CVE-2026-70991MEDIUMVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content AcquiEPSS 0.2%CVE-2023-20587HIGHImproper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code EPSS 0.2%CVE-2026-96281MEDIUMFlatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimesEPSS 0.2%CVE-2025-64715MEDIUMCilium with misconfigured toGroups in policies can lead to unrestricted egress trafficEPSS 0.2%CVE-2022-39857HIGHImproper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcastiEPSS 0.2%CVE-2022-41261MEDIUMSAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensiEPSS 0.2%CVE-2021-43986MEDIUMICSA-22-109-03 FANUC ROBOGUIDE Simulation PlatformEPSS 0.2%CVE-2022-39889MEDIUMImproper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to accessEPSS 0.2%CVE-2022-36789HIGHImproper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FEPSS 0.2%CVE-2024-40858HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access ContEPSS 0.2%CVE-2026-20638MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensionsEPSS 0.2%CVE-2025-60865HIGHInsecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the DriveEPSS 0.2%CVE-2023-32477HIGH Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged maliciousEPSS 0.2%CVE-2026-82745MEDIUMETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniquenessEPSS 0.2%CVE-2024-25576HIGHimproper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of EPSS 0.2%CVE-2025-69988MEDIUMBS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proximity can associate wEPSS 0.2%CVE-2022-39878MEDIUMImproper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via impEPSS 0.2%CVE-2022-46279MEDIUMImproper access control in the Intel(R) Retail Edge android application before version 3.0.301126-RELEASE may allow an authenticated user toEPSS 0.2%