Weaknesses of type CWE-285

1,605 results

Falha na verificação de autorização

A aplicação não valida ou valida incorretamente se um usuário tem permissão para acessar um recurso ou executar uma ação. O código assume que autenticação (saber quem é) é suficiente, ignorando autorização (saber o que pode fazer), permitindo que usuários acessem dados ou façam operações que não deveriam.

Example

Um usuário comum consegue listar faturas de outro cliente porque a API verifica se ele está logado, mas não valida se aquela fatura pertence a ele. Ou um analista consegue executar uma exclusão em massa porque o botão existe no HTML, mas o backend não checa se ele tem permissão de admin.

How to mitigate

Implemente verificações de autorização em toda operação sensível: antes de retornar dados, valide se o usuário autenticado tem acesso àquele recurso específico (RBAC, ABAC ou ACL). Teste permissões no backend sempre, nunca confie em controles apenas na UI.

CVE-2026-20661MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOEPSS 0.2%CVE-2025-1078MEDIUMAppHouseKitchen AlDente Charge Limiter XPC Service com.apphousekitchen.aldente-pro.helper shouldAcceptNewConnection improper authorizationEPSS 0.2%CVE-2025-9988MEDIUMBroadstreet <= 1.53.1 - Missing Authorization to Authenticated (Subscriber+) Advertiser CreationEPSS 0.2%CVE-2026-43756MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AnEPSS 0.2%CVE-2025-40830HIGHA vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorEPSS 0.2%CVE-2022-45128MEDIUMImproper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of sEPSS 0.2%CVE-2023-21429MEDIUMImproper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.EPSS 0.2%CVE-2022-41610MEDIUMImproper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authEPSS 0.2%CVE-2022-43465MEDIUMImproper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service viaEPSS 0.2%CVE-2025-65107MEDIUMLangfuse SSO Account Takeover via CSRF or phishing attackEPSS 0.2%CVE-2023-21432MEDIUMImproper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the ownEPSS 0.2%CVE-2026-64711MEDIUMThis issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS SoEPSS 0.2%CVE-2026-43775MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app mEPSS 0.2%CVE-2023-21424MEDIUMImproper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacEPSS 0.2%CVE-2023-21436LOWImproper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.EPSS 0.1%CVE-2026-17483MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]EPSS 0.1%CVE-2023-21423MEDIUMImproper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without pEPSS 0.1%CVE-2023-21422MEDIUMImproper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNSEPSS 0.1%CVE-2023-21452LOWImproper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.EPSS 0.1%CVE-2026-60886HIGHVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%