Weaknesses of type CWE-288

675 results

Controle de acesso inadequado

A aplicação não valida corretamente quem pode acessar um recurso, função ou dado sensível. O atacante consegue contornar as verificações de autenticação ou autorização e executa ações não permitidas (ler dados de outro usuário, modificar configurações críticas, etc.). Essa é uma das falhas mais comuns e perigosas em desenvolvimento web e APIs.

Example

Uma API de banco de dados retorna dados do usuário ID 123 quando você requisita `/api/users/123`, mas não verifica se você é realmente o dono desse perfil ou um admin. Um atacante muda o ID na URL para `/api/users/456` e acessa dados de outro cliente sem nenhuma barreira.

How to mitigate

Sempre valide a identidade do usuário (autenticação) e depois confirme explicitamente se ele tem permissão para aquele recurso (autorização). Use tokens seguros, implemente controle de acesso baseado em papéis ou atributos, e teste cada endpoint com usuários diferentes para garantir que um não acessa dados do outro.

CVE-2022-23720HIGHPingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties fileEPSS 0.2%CVE-2026-0602MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2025-40743HIGHA vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINEPSS 0.2%CVE-2026-84777HIGHWordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerabilityEPSS 0.2%CVE-2026-81796HIGHWordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-82225HIGHWordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-42745HIGHWordPress Smart Online Order for Clover plugin <= 1.6.0 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-50194HIGHSteeltoe vulnerable to management-port isolation bypass via spoofed Host headerEPSS 0.2%CVE-2025-40761HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (AllEPSS 0.2%CVE-2026-18636MEDIUMVelociraptor VFSGetBuffer API path deny list bypassEPSS 0.2%CVE-2026-12703HIGHBypass of 2FA for Connections via Unattended Access in TeamViewer for macOSEPSS 0.2%CVE-2020-11005MEDIUMInternal NCryptDecrypt method could be used externally from WindowsHello library.EPSS 0.2%CVE-2022-22189HIGHContrail Service Orchestration: An authenticated local user may have their permissions elevated via the device via management interface without authenticationEPSS 0.2%CVE-2026-81783HIGHWordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-47200MEDIUMNuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`EPSS 0.2%CVE-2026-3035MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2026-1747MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2025-13986MEDIUMDisable Login Page - Critical - Access bypass - SA-CONTRIB-2025-124EPSS 0.2%CVE-2025-3652MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpointEPSS 0.2%CVE-2026-35654MEDIUMOpenClaw < 2026.3.25 - Authorization Bypass in Microsoft Teams Feedback InvokeEPSS 0.2%