Weaknesses of type CWE-284

7,170 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-21635MEDIUMAn Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feaEPSS 0.1%CVE-2026-59912HIGHDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privilEPSS 0.1%CVE-2023-21447MEDIUMImproper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with SamsungEPSS 0.1%CVE-2025-24916HIGHImproper Access Control leads to Local Priviledge EscalationEPSS 0.1%CVE-2026-46733HIGHDell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privilegeEPSS 0.1%CVE-2026-90811MEDIUMcosmicstack-labs mercury-agent Shell Permission Manifest permissions.ts PermissionManager.checkShellCommand information disclosureEPSS 0.1%CVE-2023-21463MEDIUMImproper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.0EPSS 0.1%CVE-2026-59917HIGHDell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileEPSS 0.1%CVE-2025-20100HIGHImproper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may allow a privileged usEPSS 0.1%CVE-2025-20052MEDIUMImproper access control for some Intel(R) Graphics software may allow an authenticated user to potentially enable denial of service via locaEPSS 0.1%CVE-2024-39580MEDIUMDell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with locaEPSS 0.1%CVE-2025-23365HIGHA vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trEPSS 0.1%CVE-2022-27836HIGHImproper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 alloEPSS 0.1%CVE-2026-55978HIGHImproper access control vulnerability in CatchPulseEPSS 0.1%CVE-2024-39285MEDIUMImproper access control in UEFI firmware in some Intel(R) Server M20NTP Family may allow a privileged user to potentially enable informationEPSS 0.1%CVE-2026-70914HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.1%CVE-2026-16569MEDIUMShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock UpdateEPSS 0.1%CVE-2026-87280MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2022-40972MEDIUMImproper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable EPSS 0.1%CVE-2026-84573MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app mayEPSS 0.1%