Weaknesses of type CWE-288

675 results

Controle de acesso inadequado

A aplicação não valida corretamente quem pode acessar um recurso, função ou dado sensível. O atacante consegue contornar as verificações de autenticação ou autorização e executa ações não permitidas (ler dados de outro usuário, modificar configurações críticas, etc.). Essa é uma das falhas mais comuns e perigosas em desenvolvimento web e APIs.

Example

Uma API de banco de dados retorna dados do usuário ID 123 quando você requisita `/api/users/123`, mas não verifica se você é realmente o dono desse perfil ou um admin. Um atacante muda o ID na URL para `/api/users/456` e acessa dados de outro cliente sem nenhuma barreira.

How to mitigate

Sempre valide a identidade do usuário (autenticação) e depois confirme explicitamente se ele tem permissão para aquele recurso (autorização). Use tokens seguros, implemente controle de acesso baseado em papéis ou atributos, e teste cada endpoint com usuários diferentes para garantir que um não acessa dados do outro.

CVE-2025-1638CRITICALAlloggio Membership <= 1.1 - Authentication Bypass via Social Login Account TakeoverEPSS 0.6%CVE-2026-40022HIGHApache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtimeEPSS 0.6%CVE-2025-69101CRITICALWordPress Workreap Core plugin <= 3.4.1 - Broken Authentication vulnerabilityEPSS 0.6%CVE-2025-0181CRITICALWP Foodbakery <= 4.8 - Authentication Bypass in foodbakery_parse_requestEPSS 0.6%CVE-2025-30026MEDIUMThe AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.EPSS 0.6%CVE-2024-47406CRITICALSharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.EPSS 0.6%CVE-2024-12402CRITICALThemes Coder – Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege EscalationEPSS 0.6%CVE-2026-35422MEDIUMWindows TCP/IP Driver Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2023-50272HIGHA potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulneEPSS 0.6%CVE-2023-20018HIGHA vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote aEPSS 0.6%CVE-2022-23722PingFederate Password Reset via Authentication API MishandlingEPSS 0.6%CVE-2024-7503CRITICALWooCommerce - Social Login <= 2.7.5 - Authentication Bypass to Account TakeoverEPSS 0.6%CVE-2024-6684CRITICALAuthentication Bypass in GST Electronics' inohom Nova Panel N7EPSS 0.6%CVE-2025-3844CRITICALPeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Authentication Bypass to Account TakeoverEPSS 0.6%CVE-2024-2012CRITICALvulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or codEPSS 0.6%CVE-2026-57867HIGHMicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targetingEPSS 0.6%CVE-2026-62916CRITICALMicrosoft Entra ID Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-24000HIGHWordPress Post SMTP plugin <= 3.2.0 - Account Takeover VulnerabilityEPSS 0.6%CVE-2024-37893MEDIUMMFA bypass in oauth flow in Firefly IIIEPSS 0.6%CVE-2025-53187CRITICALUnauthenticated RCEEPSS 0.6%