Weaknesses of type CWE-284

7,078 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2025-28411CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSaveEPSS 0.6%CVE-2025-28412CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeControllerEPSS 0.6%CVE-2025-28410CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whetheEPSS 0.6%CVE-2025-28405CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus methodEPSS 0.6%CVE-2025-28402CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameterEPSS 0.6%CVE-2024-23663HIGHAn improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allEPSS 0.6%CVE-2025-28408CRITICALAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpEPSS 0.6%CVE-2022-0143CRITICALLDAP Connector: When startTLS is used then LDAP connector ignores the wrong passwordEPSS 0.6%CVE-2025-43198CRITICALThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be ableEPSS 0.6%CVE-2026-39386HIGHNeko has Self-service Privilege Escalation for Authenticated UsersEPSS 0.6%CVE-2024-43716MEDIUMAdobe Experience Manager | Improper Access Control (CWE-284)EPSS 0.6%CVE-2024-41249HIGHAn Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, whichEPSS 0.6%CVE-2024-1011MEDIUMSourceCodester Employee Management System Leave delete-leave.php access controlEPSS 0.6%CVE-2024-24568MEDIUMSuricata http2: header handling evasionEPSS 0.6%CVE-2024-43717MEDIUMAdobe Experience Manager | Improper Access Control (CWE-284)EPSS 0.6%CVE-2025-2991MEDIUMTenda FH1202 Web Management Interface AdvSetWrlmacfilter access controlEPSS 0.6%CVE-2025-3666MEDIUMTOTOLINK A3700R cstecgi.cgi setDdnsCfg access controlEPSS 0.6%CVE-2023-26473MEDIUMXWiki Platform allows unprivileged users to make arbitrary select queries using DatabaseListProperty and suggest.vmEPSS 0.6%CVE-2025-47884CRITICALIn Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values EPSS 0.6%CVE-2026-2667MEDIUMRongzhitong Visual Integrated Command and Dispatch Platform api access controlEPSS 0.6%