Weaknesses of type CWE-284

7,079 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2023-33946LOWThe Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in differenEPSS 0.6%CVE-2025-58752LOWVite's `server.fs` settings were not applied to HTML filesEPSS 0.6%CVE-2025-5409MEDIUMMist Community Edition API Token views.py create_token access controlEPSS 0.6%CVE-2023-21531HIGHAzure Service Fabric Container Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-63225CRITICALThe Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critEPSS 0.6%CVE-2025-8226MEDIUMyanyutao0402 ChanCMS find information disclosureEPSS 0.6%CVE-2022-4684HIGHImproper Access Control in usememos/memosEPSS 0.6%CVE-2026-75338CRITICALdisconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/confEPSS 0.6%CVE-2022-24038MEDIUMUnauthorized modification in Karmasis Informatics Infraskope SIEM+EPSS 0.6%CVE-2021-36913HIGHRedirection for Contact Form 7 <= 2.4.0 - Unauthenticated Options Change and Content Injection vulnerabilityEPSS 0.6%CVE-2023-43119—An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to EPSS 0.6%CVE-2024-45124MEDIUMAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2023-21860MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported versions that are affected EPSS 0.6%CVE-2023-27088HIGHfeiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform EPSS 0.6%CVE-2021-42360HIGHStarter Templates — Elementor, Gutenberg & Beaver Builder Templates <= 2.7.0 Authenticated Block Import to Stored XSSEPSS 0.6%CVE-2024-42967CRITICALIncorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains thEPSS 0.6%CVE-2022-4709MEDIUMRoyal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit ImportEPSS 0.6%CVE-2022-4708MEDIUMRoyal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions ModificationEPSS 0.6%CVE-2026-21535HIGHMicrosoft Teams Information Disclosure VulnerabilityEPSS 0.6%CVE-2022-4705MEDIUMRoyal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template ActivationEPSS 0.6%