Weaknesses of type CWE-285

1,592 results

Falha na verificação de autorização

A aplicação não valida ou valida incorretamente se um usuário tem permissão para acessar um recurso ou executar uma ação. O código assume que autenticação (saber quem é) é suficiente, ignorando autorização (saber o que pode fazer), permitindo que usuários acessem dados ou façam operações que não deveriam.

Example

Um usuário comum consegue listar faturas de outro cliente porque a API verifica se ele está logado, mas não valida se aquela fatura pertence a ele. Ou um analista consegue executar uma exclusão em massa porque o botão existe no HTML, mas o backend não checa se ele tem permissão de admin.

How to mitigate

Implemente verificações de autorização em toda operação sensível: antes de retornar dados, valide se o usuário autenticado tem acesso àquele recurso específico (RBAC, ABAC ou ACL). Teste permissões no backend sempre, nunca confie em controles apenas na UI.

CVE-2024-46942CRITICALIn OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entriesEPSS 0.4%CVE-2026-64743MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPaEPSS 0.4%CVE-2025-49594CRITICALXWiki OIDC Authenticator vulnerable to creation of token for any user with just `view` rightEPSS 0.4%CVE-2024-39415MEDIUMAn unauthorized user can export the Tax Sales ReportEPSS 0.4%CVE-2024-39413MEDIUMAn unauthorized user can export the Invoiced Sales ReportEPSS 0.4%CVE-2024-39411MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2024-39417MEDIUMAn unauthorized user can export the Shipping ReportEPSS 0.4%CVE-2022-39890MEDIUMImproper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.EPSS 0.4%CVE-2024-43706HIGHKibana Improper AuthorizationEPSS 0.4%CVE-2026-15516MEDIUMMacCMS Pro Installation Index.php step5 authorizationEPSS 0.4%CVE-2026-3185MEDIUMfeiyuchuixue sz-boot-parent API Endpoint sys-message authorizationEPSS 0.4%CVE-2025-8840MEDIUMjshERP Endpoint deleteBatch improper authorizationEPSS 0.4%CVE-2025-12288MEDIUMBdtask Pharmacy Management System User Profile edit_user authorizationEPSS 0.4%CVE-2023-33183LOWError in calendar when booking an appointment reveals the full path of the websiteEPSS 0.4%CVE-2026-1112MEDIUMSanluan PublicCMS Trade Address Deletion Endpoint TradeAddressController.java delete improper authorizationEPSS 0.4%CVE-2025-25196MEDIUMOpenFGA Authorization BypassEPSS 0.4%CVE-2026-1106MEDIUMChamilo LMS Legal Consent SocialController.php deleteLegal improper authorizationEPSS 0.4%CVE-2025-2637MEDIUMJIZHICMS Account Profile Page userinfo.html improper authorizationEPSS 0.4%CVE-2024-21761LOWAn improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to dowEPSS 0.4%CVE-2025-4672HIGHOffsprout Page Builder 2.2.1 - 2.15.2 - Authenticated (Contributor+) Privilege Escalation via permission_callback FunctionEPSS 0.4%