Weaknesses of type CWE-284

7,074 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-1933HIGHSamba: missing access check on reparse point operationsEPSS 0.9%CVE-2025-30462CRITICALA library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS EPSS 0.9%CVE-2024-45208CRITICALThe Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate EPSS 0.9%CVE-2025-30689MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.9%CVE-2025-30699MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8EPSS 0.9%CVE-2025-30696MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.0-8.0.41, 8EPSS 0.9%CVE-2025-21588MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.4.0-8.4.4 anEPSS 0.9%CVE-2024-1114MEDIUMopenBI Screen.php dlfile access controlEPSS 0.9%CVE-2021-25320CRITICALRancher: Cloud credentials can be used through proxy API by users without accessEPSS 0.9%CVE-2022-1659MEDIUMJupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of ServiceEPSS 0.9%CVE-2017-8448—An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could creatEPSS 0.9%CVE-2020-1604MEDIUMJunos OS: EX4300/EX4600/QFX3500/QFX5100 Series: Stateless IP firewall filter may fail to evaluate certain packetsEPSS 0.8%CVE-2021-4352MEDIUMJobSearch WP Job Board <= 1.8.1 - Missing Authorization to Settings ChangeEPSS 0.8%CVE-2024-28960HIGHAn issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandlesEPSS 0.8%CVE-2022-24841MEDIUMImproper Authorization in github.com/fleetdm/fleetEPSS 0.8%CVE-2021-45111HIGHImproper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to triggerEPSS 0.8%CVE-2023-22920CRITICALA security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfEPSS 0.8%CVE-2023-1647HIGHImproper Access Control in calcom/cal.comEPSS 0.8%CVE-2021-33013HIGHmySCADA myPRO Improper Access ControlEPSS 0.8%CVE-2022-32257CRITICALA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web servicEPSS 0.8%