Weaknesses of type CWE-285

1,605 results

Falha na verificação de autorização

A aplicação não valida ou valida incorretamente se um usuário tem permissão para acessar um recurso ou executar uma ação. O código assume que autenticação (saber quem é) é suficiente, ignorando autorização (saber o que pode fazer), permitindo que usuários acessem dados ou façam operações que não deveriam.

Example

Um usuário comum consegue listar faturas de outro cliente porque a API verifica se ele está logado, mas não valida se aquela fatura pertence a ele. Ou um analista consegue executar uma exclusão em massa porque o botão existe no HTML, mas o backend não checa se ele tem permissão de admin.

How to mitigate

Implemente verificações de autorização em toda operação sensível: antes de retornar dados, valide se o usuário autenticado tem acesso àquele recurso específico (RBAC, ABAC ou ACL). Teste permissões no backend sempre, nunca confie em controles apenas na UI.

CVE-2025-43289MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A maliciEPSS 0.1%CVE-2026-2974LOWAliasVault App Backup aliasvault.xml backupEPSS 0.1%CVE-2026-47053MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2025-68712MEDIUMSpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentiEPSS 0.1%CVE-2026-60842MEDIUMVulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affectEPSS 0.1%CVE-2023-44123MEDIUMBluetooth - Theft and (over-)write of arbitrary files with system privilege via PendingIntent hijackingEPSS 0.1%CVE-2023-24476LOWPTC Vuforia Studio Improper AuthorizationEPSS 0.1%CVE-2025-8532MEDIUMIDOR in Bimser's eBA Document and Workflow Management SystemEPSS 0.1%CVE-2023-44125MEDIUMPersonalized service - Theft and (over-)write of arbitrary files with system privilege via PendingIntent hijackingEPSS 0.1%CVE-2026-21097MEDIUMImproper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary EPSS 0.1%CVE-2023-28556HIGHImproper Authorization in HLOSEPSS 0.1%CVE-2026-0072CRITICALIn addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead EPSS 0.1%CVE-2026-60957MEDIUMVulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.1%CVE-2026-60911MEDIUMVulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.1%CVE-2026-20656LOWA logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. AnEPSS 0.1%CVE-2026-62563MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%CVE-2022-39905MEDIUMImplicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive informatiEPSS 0.1%CVE-2021-25459MEDIUMAn improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockEPSS 0.1%CVE-2026-20666MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sEPSS 0.1%CVE-2024-51525MEDIUMPermission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiEPSS 0.1%