Weaknesses of type CWE-284

7,070 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2023-41772HIGHWin32k Elevation of Privilege VulnerabilityEPSS 11.8%CVE-2025-3663MEDIUMTOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access controlEPSS 11.3%CVE-2026-33478CRITICALAVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command InjectionEPSS 11.2%CVE-2022-20780CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 11.2%CVE-2022-20777CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 11.1%CVE-2025-2993MEDIUMTenda FH1202 default.cfg access controlEPSS 10.9%CVE-2018-10630—For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication diEPSS 10.9%CVE-2025-2546MEDIUMD-Link DIR-618/DIR-605L Firewall Service formAdvFirewall access controlEPSS 10.8%CVE-2024-1675HIGHInsufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictiEPSS 10.6%CVE-2022-20779CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 10.5%CVE-2023-28810MEDIUMSome access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify dEPSS 10.4%CVE-2018-7364HIGHAll versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due tEPSS 10.3%CVE-2023-26347HIGHCVE-2023-38205 issues | ColdFusion Admin Panel AccessEPSS 10.1%CVE-2025-48999MEDIUMDataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE VulnerabilityEPSS 10.0%CVE-2021-24215—Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege EscalationEPSS 9.7%CVE-2026-35616CRITICALA improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauEPSS 9.1%KEVCVE-2022-1631MEDIUMUsers Account Pre-Takeover or Users Account Takeover. in microweber/microweberEPSS 8.8%CVE-2017-12171MEDIUMA regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuratEPSS 8.1%CVE-2019-11634CRITICALCitrix Workspace App before 1904 for Windows has Incorrect Access Control.EPSS 8.0%KEVCVE-2018-15640HIGHImproper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated prEPSS 7.8%