Weaknesses of type CWE-284

7,085 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2025-58724HIGHArc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-6443HIGHMikrotik RouterOS VXLAN Source IP Improper Access Control VulnerabilityEPSS 0.6%CVE-2024-0366MEDIUMStarbox – the Author Box for Humans <= 3.4.7 - Insecure Direct Object ReferenceEPSS 0.6%CVE-2021-41834MEDIUMJFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-pEPSS 0.6%CVE-2024-1088MEDIUMPassword Protected Store for WooCommerce <= 2.2 - Information Exposure via REST APIEPSS 0.6%CVE-2022-4807HIGHImproper Access Control in usememos/memosEPSS 0.6%CVE-2024-12478MEDIUMInvoicePlane 1 upload_file unrestricted uploadEPSS 0.6%CVE-2023-40730HIGHA vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks suffiEPSS 0.6%CVE-2025-71380HIGHn8n - Arbitrary Command Execution via Execute Command NodeEPSS 0.6%CVE-2022-3186HIGHDataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the dEPSS 0.6%CVE-2023-0858LOWImproper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on theEPSS 0.6%CVE-2025-12201MEDIUMajayrandhawa User-Management-PHP-MYSQL User Management edit-user.php unrestricted uploadEPSS 0.6%CVE-2023-34106MEDIUMGLPI vulnerable to unauthorized access to User dataEPSS 0.6%CVE-2023-34107MEDIUMGLPI vulnerable to unauthorized access to KnowbaseItem dataEPSS 0.6%CVE-2025-43586HIGHAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2025-67014HIGHIncorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers EPSS 0.6%CVE-2025-3585MEDIUMwestboy CicadasCMS JSP Parser upload unrestricted uploadEPSS 0.6%CVE-2024-20657HIGHWindows Group Policy Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-2938MEDIUMSourceCodester Student Result Management System update_smtp.php access controlEPSS 0.6%CVE-2021-28511MEDIUMThis advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches t ...EPSS 0.6%