Weaknesses of type CWE-285

1,605 results

Falha na verificação de autorização

A aplicação não valida ou valida incorretamente se um usuário tem permissão para acessar um recurso ou executar uma ação. O código assume que autenticação (saber quem é) é suficiente, ignorando autorização (saber o que pode fazer), permitindo que usuários acessem dados ou façam operações que não deveriam.

Example

Um usuário comum consegue listar faturas de outro cliente porque a API verifica se ele está logado, mas não valida se aquela fatura pertence a ele. Ou um analista consegue executar uma exclusão em massa porque o botão existe no HTML, mas o backend não checa se ele tem permissão de admin.

How to mitigate

Implemente verificações de autorização em toda operação sensível: antes de retornar dados, valide se o usuário autenticado tem acesso àquele recurso específico (RBAC, ABAC ou ACL). Teste permissões no backend sempre, nunca confie em controles apenas na UI.

CVE-2026-44362MEDIUMOP-TEE's subkey rollback protection can be bypassed with older subkey versionsEPSS 0.2%CVE-2026-18367CRITICALA privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2EPSS 0.2%CVE-2023-21440MEDIUMImproper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.EPSS 0.2%CVE-2022-36870MEDIUMPending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global aEPSS 0.2%CVE-2025-22175MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22169MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2022-36872MEDIUMPending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackEPSS 0.2%CVE-2022-36871MEDIUMPending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackeEPSS 0.2%CVE-2025-2528LOWImproper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use EPSS 0.2%CVE-2025-10736MEDIUMReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data ManipulationEPSS 0.2%CVE-2025-53709MEDIUMAccess control issues impacting secure-upload serviceEPSS 0.2%CVE-2025-46296MEDIUMAn authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access adminiEPSS 0.2%CVE-2023-2782MEDIUMSensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) befoEPSS 0.2%CVE-2026-46620MEDIUMe107: CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check()EPSS 0.2%CVE-2023-26466HIGHA user with non-Admin access can change a configuration file on the client to modify the Server URL.EPSS 0.2%CVE-2023-25517HIGH NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources fEPSS 0.2%CVE-2022-4062HIGHA CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gEPSS 0.2%CVE-2023-22636MEDIUMAn unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allowEPSS 0.2%CVE-2023-35022LOWIBM InfoSphere Information Server improper authenticationEPSS 0.2%CVE-2025-1078MEDIUMAppHouseKitchen AlDente Charge Limiter XPC Service com.apphousekitchen.aldente-pro.helper shouldAcceptNewConnection improper authorizationEPSS 0.2%