Weaknesses of type CWE-284

7,076 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-7198CRITICALCWE-284: Improper Access Control in web services in Progress SitefinityEPSS 0.6%CVE-2016-10549—Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration wEPSS 0.6%CVE-2024-48955HIGHBroken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, theEPSS 0.6%CVE-2021-24500—Workreap theme < 2.2.2 - Multiple CSRF + IDOR VulnerabilitiesEPSS 0.6%CVE-2026-5526MEDIUMTenda 4G03 Pro httpd access controlEPSS 0.6%CVE-2019-5014MEDIUMAn exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.EPSS 0.6%CVE-2023-43696HIGH Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous acceEPSS 0.6%CVE-2025-7565MEDIUMLB-LINK BL-AC3600 Web Management Interface lighttpd.cgi geteasycfg information disclosureEPSS 0.6%CVE-2025-45343CRITICALAn issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module iEPSS 0.6%CVE-2023-7223MEDIUMTotolink T6 cstecgi.cgi access controlEPSS 0.6%CVE-2015-10057MEDIUMLittle Apps Little Software Stats Password Reset class.securelogin.php access controlEPSS 0.6%CVE-2024-45118MEDIUMAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2026-47396CRITICALPraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unsetEPSS 0.6%CVE-2025-32470HIGHUnauthenticated change of IP adressEPSS 0.6%CVE-2025-66390CRITICALIn Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in TenantEPSS 0.6%CVE-2022-45431HIGHSome Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access contrEPSS 0.6%CVE-2020-10143HIGHMacrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged seEPSS 0.6%CVE-2024-46432HIGHTenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setEPSS 0.6%CVE-2021-46270LOWJFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repositoryEPSS 0.6%CVE-2026-51718CRITICALIncorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove EPSS 0.6%