Weaknesses of type CWE-284

7,074 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2023-28808CRITICALSome Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. ThEPSS 0.8%CVE-2023-39743—lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.EPSS 0.8%CVE-2023-0451HIGHEconolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and confiEPSS 0.8%CVE-2022-33925MEDIUMDell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could pEPSS 0.8%CVE-2024-13067MEDIUMCodeAstro Online Food Ordering System All Users Page all_users.php access controlEPSS 0.8%CVE-2022-34827HIGHCarel Boss Mini 1.5.0 has Improper Access Control.EPSS 0.8%CVE-2025-7076MEDIUMBlackVue Dashcam 590X Configuration upload.cgi access controlEPSS 0.8%CVE-2023-6930CRITICALImproper Access Control in EuroTel ETL3100EPSS 0.8%CVE-2023-24425MEDIUMJenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentiaEPSS 0.8%CVE-2021-40413HIGHAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_201EPSS 0.8%CVE-2026-75998HIGHColdFusion | Improper Access Control (CWE-284)EPSS 0.8%CVE-2025-55238HIGHDynamics 365 FastTrack Implementation Assets Information Disclosure VulnerabilityEPSS 0.8%CVE-2025-21185MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-46629MEDIUMLack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to performEPSS 0.8%CVE-2025-21587HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). EPSS 0.8%CVE-2025-48983CRITICALA vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructurEPSS 0.8%CVE-2022-31708MEDIUMvRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the ModEPSS 0.8%CVE-2020-7531—A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to plaEPSS 0.8%CVE-2022-3067MEDIUMAn issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versioEPSS 0.8%CVE-2026-73749CRITICALUnauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.8%