Weaknesses of type CWE-284

7,078 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-54745CRITICALKubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=trueEPSS 0.6%CVE-2023-0811CRITICAL Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a EPSS 0.6%CVE-2026-90898CRITICALBifrost unauthenticated remote code execution via MCP stdio client registrationEPSS 0.6%CVE-2022-46892CRITICALIn Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.EPSS 0.6%CVE-2025-29515CRITICALIncorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modiEPSS 0.6%CVE-2022-43977CRITICALAn issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn sEPSS 0.6%CVE-2022-47699CRITICALCOMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control.EPSS 0.6%CVE-2025-0206MEDIUMcode-projects Online Shoe Store index.php access controlEPSS 0.6%CVE-2022-44212MEDIUMIn GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.EPSS 0.6%CVE-2023-28844MEDIUMUser without download rights can download older version of that file in nextcloud serverEPSS 0.6%CVE-2020-27873MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1EPSS 0.6%CVE-2026-51754CRITICALIncorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwritEPSS 0.6%CVE-2023-47031CRITICALAn issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsersEPSS 0.6%CVE-2022-31055HIGHImproper Access Control in kctfEPSS 0.6%CVE-2026-52844HIGHCaddy: Windows `file_server` path authorization bypass via encoded backslashEPSS 0.6%CVE-2022-38546MEDIUMA DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker EPSS 0.6%CVE-2025-3675MEDIUMTOTOLINK A3700R cstecgi.cgi setL2tpServerCfg access controlEPSS 0.6%CVE-2025-3237MEDIUMTenda FH1202 wrlwpsset access controlEPSS 0.6%CVE-2026-51689CRITICALIncorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmwEPSS 0.6%CVE-2022-2702HIGHSourceCodester Company Website CMS Cookie site-settings.php access controlEPSS 0.6%