Weaknesses of type CWE-285

1,600 results

Falha na verificação de autorização

A aplicação não valida ou valida incorretamente se um usuário tem permissão para acessar um recurso ou executar uma ação. O código assume que autenticação (saber quem é) é suficiente, ignorando autorização (saber o que pode fazer), permitindo que usuários acessem dados ou façam operações que não deveriam.

Example

Um usuário comum consegue listar faturas de outro cliente porque a API verifica se ele está logado, mas não valida se aquela fatura pertence a ele. Ou um analista consegue executar uma exclusão em massa porque o botão existe no HTML, mas o backend não checa se ele tem permissão de admin.

How to mitigate

Implemente verificações de autorização em toda operação sensível: antes de retornar dados, valide se o usuário autenticado tem acesso àquele recurso específico (RBAC, ABAC ou ACL). Teste permissões no backend sempre, nunca confie em controles apenas na UI.

CVE-2025-60784MEDIUMA vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.EPSS 0.4%CVE-2023-22938MEDIUMPermissions Validation Failure in the ‘sendemail’ REST API Endpoint in Splunk EnterpriseEPSS 0.4%CVE-2025-14546MEDIUMVersions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the EPSS 0.4%CVE-2025-10374MEDIUMShenzhen Sixun Business Management System OperatorStop improper authorizationEPSS 0.4%CVE-2025-63691CRITICALIn pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interfaEPSS 0.4%CVE-2026-28839MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app mayEPSS 0.4%CVE-2024-58367HIGHSurrealDB before 2.0.4 Improper Authorization via SELECT PermissionsEPSS 0.4%CVE-2026-75792MEDIUMIBM Sterling Secure Proxy is vulnerable to multiple issuesEPSS 0.4%CVE-2026-20285MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2026-20286MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2025-27399MEDIUMMastodon's domain blocks & rationales ignore user approval when visibility set as "users"EPSS 0.4%CVE-2025-6713HIGHMongoDB Server may be susceptible to privilege escalation due to $mergeCursors stageEPSS 0.4%CVE-2024-38370MEDIUMGLPI allows API document download without rightsEPSS 0.4%CVE-2025-54585HIGHGitProxy is vulnerable to a new branch approval exploitEPSS 0.4%CVE-2022-40521HIGHImproper authorization in ModemEPSS 0.4%CVE-2023-33020HIGHImproper Authorization in WLAN HostEPSS 0.4%CVE-2026-49977MEDIUMtarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookiesEPSS 0.4%CVE-2024-13241CRITICALOpen Social - Moderately critical - Information Disclosure - SA-CONTRIB-2024-005EPSS 0.4%CVE-2026-1193MEDIUMMineAdmin View view improper authorizationEPSS 0.4%CVE-2019-13528—A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-800EPSS 0.4%