Weaknesses of type CWE-288

675 results

Controle de acesso inadequado

A aplicação não valida corretamente quem pode acessar um recurso, função ou dado sensível. O atacante consegue contornar as verificações de autenticação ou autorização e executa ações não permitidas (ler dados de outro usuário, modificar configurações críticas, etc.). Essa é uma das falhas mais comuns e perigosas em desenvolvimento web e APIs.

Example

Uma API de banco de dados retorna dados do usuário ID 123 quando você requisita `/api/users/123`, mas não verifica se você é realmente o dono desse perfil ou um admin. Um atacante muda o ID na URL para `/api/users/456` e acessa dados de outro cliente sem nenhuma barreira.

How to mitigate

Sempre valide a identidade do usuário (autenticação) e depois confirme explicitamente se ele tem permissão para aquele recurso (autorização). Use tokens seguros, implemente controle de acesso baseado em papéis ou atributos, e teste cada endpoint com usuários diferentes para garantir que um não acessa dados do outro.

CVE-2026-40781HIGHWordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2023-20247MEDIUMA vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense EPSS 0.3%CVE-2022-26865MEDIUMDell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physiEPSS 0.3%CVE-2026-88861HIGHCapgo AAL1 Session MFA Bypass via Direct RBAC AuthorizationEPSS 0.3%CVE-2026-42760HIGHWordPress Backup and Staging by WP Time Capsule plugin <= 1.22.25 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2026-4524MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.3%CVE-2026-25471HIGHWordPress Admin Safety Guard plugin <= 1.2.6 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2026-77103HIGHCommServe Information DisclosureEPSS 0.3%CVE-2026-41308MEDIUMPassword Pusher: JSON API `/p.json` file upload alias bypasses file-push authenticationEPSS 0.3%CVE-2026-66425MEDIUMWordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2025-24456MEDIUMIn JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mappingEPSS 0.3%CVE-2026-22049HIGHONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to thEPSS 0.3%CVE-2026-35661MEDIUMOpenClaw < 2026.3.25 - Telegram DM-Scoped Inline Button Callback Authorization BypassEPSS 0.3%CVE-2025-30112HIGHOn 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attaEPSS 0.3%CVE-2022-23719HIGHPingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requestsEPSS 0.3%CVE-2026-35647MEDIUMOpenClaw < 2026.3.25 - Direct Message Policy Bypass via Verification NoticesEPSS 0.3%CVE-2026-6768CRITICALMitigation bypass in the Networking: Cookies componentEPSS 0.3%CVE-2026-93928HIGHWordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2026-18047MEDIUMDogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slashEPSS 0.3%CVE-2025-58133MEDIUMZoom Rooms Clients - Authentication BypassEPSS 0.3%