Weaknesses of type CWE-284

7,169 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-61313MEDIUMVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.2%CVE-2026-60884MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that aEPSS 0.2%CVE-2026-71145MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.2%CVE-2022-3746MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2022-37410HIGHImproper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enablEPSS 0.2%CVE-2023-28051HIGH Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentiallyEPSS 0.2%CVE-2022-38466—A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecuEPSS 0.2%CVE-2025-43328LOWA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitivEPSS 0.2%CVE-2025-57197MEDIUMIn the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change featuEPSS 0.2%CVE-2022-43702—Incomplete verification of installation file signatureEPSS 0.2%CVE-2026-71084MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.EPSS 0.2%CVE-2024-30211MEDIUMImproper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potenEPSS 0.2%CVE-2025-69634CRITICALCross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field EPSS 0.2%CVE-2026-28833MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS EPSS 0.2%CVE-2025-2954MEDIUMmannaandpoem OpenManus File file_saver.py execute access controlEPSS 0.2%CVE-2023-21457MEDIUMImproper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without relatEPSS 0.2%CVE-2023-42969LOWAn app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOEPSS 0.2%CVE-2026-104678LOWCP Media Player < 1.3.4 - Contributor+ Media Player Settings UpdateEPSS 0.2%CVE-2024-27792MEDIUMThis issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to acEPSS 0.2%CVE-2023-31271MEDIUMImproper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalEPSS 0.2%