Weaknesses of type CWE-284

7,074 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2024-43456MEDIUMWindows Remote Desktop Services Tampering VulnerabilityEPSS 0.7%CVE-2016-4427—In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.EPSS 0.7%CVE-2020-2500CRITICALThis improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensEPSS 0.7%CVE-2023-28645MEDIUMSecure view can be bypassed by using internal API endpoint in Nextcloud richdocumentsEPSS 0.7%CVE-2026-2861MEDIUMFoswiki Changes/Viewfile/Oops information disclosureEPSS 0.7%CVE-2022-4331MEDIUMAn issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15EPSS 0.7%CVE-2023-46712MEDIUMA improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacEPSS 0.7%CVE-2023-0319MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.EPSS 0.7%CVE-2017-16766—An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 aEPSS 0.7%CVE-2025-30460HIGHA permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOSEPSS 0.7%CVE-2025-2218MEDIUMLoveCards LoveCardsV2 Setting other access controlEPSS 0.7%CVE-2025-43233CRITICALThis issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13EPSS 0.7%CVE-2024-1308HIGHWooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink ModificationEPSS 0.7%CVE-2023-22335—Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attEPSS 0.7%CVE-2024-45432HIGHOpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The EPSS 0.7%CVE-2024-10993MEDIUMCodezips Online Institute Management System manage_website.php unrestricted uploadEPSS 0.7%CVE-2022-4689HIGHImproper Access Control in usememos/memosEPSS 0.7%CVE-2023-6773MEDIUMCodeAstro POS and Inventory Management System User Creation register_account access controlEPSS 0.7%CVE-2024-13104MEDIUMD-Link DIR-816 A2 WiFi Settings form2AdvanceSetup.cgi access controlEPSS 0.7%CVE-2023-0661MEDIUMImproper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data. EPSS 0.7%