Weaknesses of type CWE-285

1,605 results

Falha na verificação de autorização

A aplicação não valida ou valida incorretamente se um usuário tem permissão para acessar um recurso ou executar uma ação. O código assume que autenticação (saber quem é) é suficiente, ignorando autorização (saber o que pode fazer), permitindo que usuários acessem dados ou façam operações que não deveriam.

Example

Um usuário comum consegue listar faturas de outro cliente porque a API verifica se ele está logado, mas não valida se aquela fatura pertence a ele. Ou um analista consegue executar uma exclusão em massa porque o botão existe no HTML, mas o backend não checa se ele tem permissão de admin.

How to mitigate

Implemente verificações de autorização em toda operação sensível: antes de retornar dados, valide se o usuário autenticado tem acesso àquele recurso específico (RBAC, ABAC ou ACL). Teste permissões no backend sempre, nunca confie em controles apenas na UI.

CVE-2022-22268MEDIUMIncorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox GuEPSS 0.1%CVE-2024-42032MEDIUMAccess permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect serviceEPSS 0.1%CVE-2024-43051MEDIUMImproper Authorization in SPS-HLOSEPSS 0.1%CVE-2026-12065LOWGroww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url schemeEPSS 0.1%CVE-2022-36852LOWImproper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application daEPSS 0.1%CVE-2026-12190MEDIUMGenspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url schemeEPSS 0.1%CVE-2026-12189MEDIUMMoovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url schemeEPSS 0.1%CVE-2024-38425MEDIUMImproper Authorization in PerformanceEPSS 0.1%CVE-2021-25382MEDIUMAn improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contentsEPSS 0.1%CVE-2022-22269MEDIUMKeeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a localEPSS 0.1%CVE-2026-78236HIGHInsecure PIN derivation mechanism in Admin By Request (ABR)EPSS 0.1%CVE-2022-22267MEDIUMImplicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running applicationEPSS 0.1%CVE-2022-22272MEDIUMImproper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE EPSS 0.1%CVE-2022-30757MEDIUMImproper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permissioEPSS 0.1%CVE-2026-0017HIGHIn onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could leadEPSS 0.1%CVE-2021-25460MEDIUMAn improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BEPSS 0.1%CVE-2025-30508MEDIUMImproper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow a denial of serviEPSS 0.1%CVE-2022-33722MEDIUMImplicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC addressEPSS 0.1%CVE-2022-33702MEDIUMImproper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass KnoxgEPSS 0.1%CVE-2026-16925HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%