Weaknesses of type CWE-284

7,078 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2024-57190CRITICALErxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that containEPSS 0.6%CVE-2026-81941HIGHLangflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardsEPSS 0.6%CVE-2025-24968HIGHBusiness Logic And Unrestricted Project Deletion Lead To Take Over the System in reNgineEPSS 0.6%CVE-2025-4977MEDIUMNetgear DGND3700 BRS_top.html information disclosureEPSS 0.6%CVE-2024-0631MEDIUMDuitku Payment Gateway <= 2.11.6 - Missing Authorization via check_duitku_responseEPSS 0.6%CVE-2022-44211HIGHIn GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.EPSS 0.6%CVE-2025-4980MEDIUMNetgear DGND3700 mini_http currentsetting.htm information disclosureEPSS 0.6%CVE-2023-5240—Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAEPSS 0.6%CVE-2025-4271MEDIUMTOTOLINK A720R cstecgi.cgi information disclosureEPSS 0.6%CVE-2022-41970LOWNextcloud Server's disabled download shares still allow download through preview imagesEPSS 0.6%CVE-2022-4567HIGHImproper Access Control in openemr/openemrEPSS 0.6%CVE-2025-48986HIGHAuthorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email addreEPSS 0.6%CVE-2026-51679CRITICALIncorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the EPSS 0.6%CVE-2023-40170MEDIUMcross-site inclusion (XSSI) of files in jupyter-serverEPSS 0.6%CVE-2022-28173CRITICALThe web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permissEPSS 0.6%CVE-2024-31964HIGHA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.6%CVE-2024-21074HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Finance LOV). Supported versions that are affecEPSS 0.6%CVE-2025-30710MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected arEPSS 0.6%CVE-2024-42480HIGHKamaji's RBAC Roles for `etcd` are not disjunctEPSS 0.6%CVE-2026-90898CRITICALBifrost unauthenticated remote code execution via MCP stdio client registrationEPSS 0.6%