Weaknesses of type CWE-284

7,078 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-51645CRITICALIncorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the EPSS 0.6%CVE-2026-51693CRITICALIncorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge EPSS 0.6%CVE-2026-51765CRITICALIncorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to inserEPSS 0.6%CVE-2026-51674CRITICALIncorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure fEPSS 0.6%CVE-2026-51764CRITICALIncorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to EPSS 0.6%CVE-2026-51699CRITICALIncorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internEPSS 0.6%CVE-2026-51691CRITICALIncorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulatEPSS 0.6%CVE-2026-51762CRITICALIncorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or cleanEPSS 0.6%CVE-2026-51767CRITICALIncorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset paiEPSS 0.6%CVE-2026-51751CRITICALIncorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a spEPSS 0.6%CVE-2026-51741CRITICALIncorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diEPSS 0.6%CVE-2026-51750CRITICALIncorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan anEPSS 0.6%CVE-2026-51724CRITICALIncorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove SmarEPSS 0.6%CVE-2026-51686CRITICALIncorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigureEPSS 0.6%CVE-2026-51769CRITICALIncorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to resEPSS 0.6%CVE-2026-51744CRITICALIncorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force EPSS 0.6%CVE-2025-14748MEDIUMNingyuanda TC155 ONVIF Device Management Service device_service access controlEPSS 0.6%CVE-2025-28406CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameterEPSS 0.6%CVE-2025-28413CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController componentEPSS 0.6%CVE-2025-28411CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSaveEPSS 0.6%