Weaknesses of type CWE-284

7,085 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2026-37235HIGHFlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation functiEPSS 0.6%CVE-2024-24486CRITICALAn issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA commaEPSS 0.6%CVE-2025-3558MEDIUMghostxbh uzy-ssm-mall uploadUserHeadImage unrestricted uploadEPSS 0.6%CVE-2021-28511MEDIUMThis advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches t ...EPSS 0.6%CVE-2026-2768CRITICALSandbox escape in the Storage: IndexedDB componentEPSS 0.6%CVE-2023-47536LOWAn improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProEPSS 0.6%CVE-2022-3780HIGHDatabase connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deletEPSS 0.6%CVE-2025-28407HIGHAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properEPSS 0.6%CVE-2025-28409HIGHAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properEPSS 0.6%CVE-2026-54408HIGHA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to byEPSS 0.6%CVE-2025-21359HIGHWindows Kernel Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-20706CRITICALGitea repository archive downloads bypass token scope checksEPSS 0.6%CVE-2022-28760MEDIUMZoom On-Premise Deployments: Improper Access ControlEPSS 0.6%CVE-2024-21666MEDIUMPimcore Customer Data Framework Improper Access Control allows unprivileged user to access customers duplicates listEPSS 0.6%CVE-2023-29130CRITICALA vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the coEPSS 0.6%CVE-2026-7686MEDIUMeyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access controlEPSS 0.6%CVE-2021-23178HIGHImproper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online paymentsEPSS 0.6%CVE-2024-42797CRITICALAn Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. ThiEPSS 0.6%CVE-2025-4064MEDIUMScriptAndTools Online-Travling-System viewenquiry.php access controlEPSS 0.6%CVE-2025-64660HIGHGitHub Copilot and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.6%