Weaknesses of type CWE-284

7,074 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2022-39406HIGHVulnerability in the PeopleSoft Enterprise Common Components product of Oracle PeopleSoft (component: Approval Framework). The supported verEPSS 0.7%CVE-2025-0582MEDIUMitsourcecode Farm Management System add-pig.php unrestricted uploadEPSS 0.7%CVE-2026-2684MEDIUMTsinghua Unigroup Electronic Archives System uploadFile.html unrestricted uploadEPSS 0.7%CVE-2023-24028CRITICALIn MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.EPSS 0.7%CVE-2019-11786MEDIUMImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modifyEPSS 0.7%CVE-2026-35425HIGHAzure API Management (APIM) Remote Code Execution VulnerabilityEPSS 0.7%CVE-2021-34627MEDIUMWP Upload Restriction <= 2.2.3 - Missing Access Control in getSelectedMimeTypesByRole functionEPSS 0.7%CVE-2026-26145MEDIUMMicrosoft Azure Synapse Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2021-4364MEDIUMJobSearch WP Job Board < = 1.8.1 - Missing Authorization on jobsearch_update_job_import_schedule_call() functionEPSS 0.7%CVE-2022-39310MEDIUMMalicious agent may be able to impersonate another agent in GoCDEPSS 0.7%CVE-2026-2983MEDIUMSourceCodester Student Result Management System Bulk Import import_users.php access controlEPSS 0.7%CVE-2023-24688MEDIUMAn issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is diEPSS 0.7%CVE-2021-4089MEDIUMImproper Access Control in snipe/snipe-itEPSS 0.7%CVE-2025-15082MEDIUMTOZED ZLT M30s Web Management proc_post information disclosureEPSS 0.7%CVE-2026-26325HIGHOpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvalsEPSS 0.7%CVE-2022-46354MEDIUMA vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALAEPSS 0.7%CVE-2025-43184CRITICALThis issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.7, maEPSS 0.7%CVE-2022-40036MEDIUMAn issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via EPSS 0.7%CVE-2023-2901MEDIUMNFine Rapid Development Platform access controlEPSS 0.7%CVE-2025-50900CRITICALAn issue was discovered in getrebuild/rebuild 4.0.4. The affected source code class is com.rebuild.web.RebuildWebInterceptor, and the affectEPSS 0.7%