Weaknesses of type CWE-284

7,074 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2024-31759HIGHAn issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.EPSS 0.9%CVE-2021-23203HIGHImproper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackEPSS 0.9%CVE-2023-22102HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and EPSS 0.9%CVE-2023-36561HIGHAzure DevOps Server Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2019-0041MEDIUMJunos OS: EX4300-MP Series: IP transit traffic can reach the control plane via loopback interface.EPSS 0.9%CVE-2021-41298HIGHECOA BAS controller - Improper Access ControlEPSS 0.9%CVE-2024-11961MEDIUMGuangzhou Huayi Intelligent Technology Jeewms WmOmNoticeHController.java preHandle information disclosureEPSS 0.9%CVE-2022-40798HIGHOcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request withEPSS 0.9%CVE-2021-40416HIGHAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_201EPSS 0.9%CVE-2023-3431MEDIUMImproper Access Control in plantuml/plantumlEPSS 0.9%CVE-2026-58630CRITICALAzure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2021-25672—A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace modulEPSS 0.9%CVE-2024-21145MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). SEPSS 0.9%CVE-2020-3126LOWCisco Webex Meetings Multimedia Viewer VulnerabilityEPSS 0.9%CVE-2023-24468—Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2EPSS 0.9%CVE-2025-0650HIGHOvn: egress acls may be bypassed via specially crafted udp packetEPSS 0.9%CVE-2026-66309CRITICALAzure SQL Database Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2022-31475MEDIUMWordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerabilityEPSS 0.9%CVE-2026-24306CRITICALAzure Front Door Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2020-25238—A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). ManipulatingEPSS 0.9%