Weaknesses of type CWE-284

7,088 results

Controle de acesso inadequado a recursos

A aplicação falha em validar ou impõe regras insuficientes para determinar quem pode acessar um recurso (arquivo, API, dados, funcionalidade). Um usuário não autorizado consegue contornar essas restrições e acessar o que não deveria, seja por falta de autenticação, autorização fraca ou lógica de controle de acesso bugada.

Example

Um sistema de gestão de RH permite que qualquer funcionário logado acesse `/api/salarios/{id}` substituindo o ID na URL. Sem verificar se o usuário é gestor ou RH, a API retorna dados salariais de qualquer pessoa da empresa. Um dev junior consegue ver quanto ganha o CTO.

How to mitigate

Implemente verificação explícita de permissões antes de qualquer acesso: confirme autenticação (quem é), autorização (o que pode fazer) e aplique o princípio do menor privilégio. Use listas de controle de acesso (ACL), roles bem definidos e sempre valide no backend, nunca confie em dados do cliente.

CVE-2025-31698HIGHApache Traffic Server: Client IP address from PROXY protocol is not used for ACLEPSS 0.6%CVE-2025-59500HIGHAzure Notification Service Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-32834MEDIUMAn access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security UEPSS 0.6%CVE-2023-51070HIGHAn access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjusEPSS 0.6%CVE-2025-1834MEDIUMzj1983 zz resolve unrestricted uploadEPSS 0.6%CVE-2025-0346MEDIUMcode-projects Content Management System Publish News Page publishnews.php unrestricted uploadEPSS 0.6%CVE-2023-21905MEDIUMVulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). EPSS 0.6%CVE-2026-2666MEDIUMmingSoft MCMS Template Archive uploadTemplate.do unrestricted uploadEPSS 0.6%CVE-2024-45122MEDIUMAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2024-36080CRITICALWestermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is EPSS 0.6%CVE-2026-28699HIGHGitea Basic Auth bypasses OAuth2 access token scopesEPSS 0.6%CVE-2025-66430CRITICALPlesk 18.0 has Incorrect Access Control.EPSS 0.6%CVE-2024-42559CRITICALAn issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providEPSS 0.6%CVE-2024-38873MEDIUMAn issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extensioEPSS 0.5%CVE-2022-21586MEDIUMVulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supportEPSS 0.5%CVE-2022-46676MEDIUM Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users unEPSS 0.5%CVE-2022-47037HIGHSiklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.EPSS 0.5%CVE-2026-86284MEDIUMjaychouchannel Tourism-Management-System CommonController.java getOption information disclosureEPSS 0.5%CVE-2022-46677MEDIUM Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroupEPSS 0.5%CVE-2026-44774MEDIUMTraefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=falseEPSS 0.5%