Weaknesses of type CWE-288

675 results

Controle de acesso inadequado

A aplicação não valida corretamente quem pode acessar um recurso, função ou dado sensível. O atacante consegue contornar as verificações de autenticação ou autorização e executa ações não permitidas (ler dados de outro usuário, modificar configurações críticas, etc.). Essa é uma das falhas mais comuns e perigosas em desenvolvimento web e APIs.

Example

Uma API de banco de dados retorna dados do usuário ID 123 quando você requisita `/api/users/123`, mas não verifica se você é realmente o dono desse perfil ou um admin. Um atacante muda o ID na URL para `/api/users/456` e acessa dados de outro cliente sem nenhuma barreira.

How to mitigate

Sempre valide a identidade do usuário (autenticação) e depois confirme explicitamente se ele tem permissão para aquele recurso (autorização). Use tokens seguros, implemente controle de acesso baseado em papéis ou atributos, e teste cada endpoint com usuários diferentes para garantir que um não acessa dados do outro.

CVE-2023-3277CRITICALMStore API <= 4.10.7 - Unauthorized Account Access and Privilege EscalationEPSS 2.9%CVE-2020-15633HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-EPSS 2.8%CVE-2017-9944A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 8EPSS 2.7%CVE-2020-27865HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware versionEPSS 2.6%CVE-2026-24207CRITICALNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of thisEPSS 2.6%CVE-2020-14485OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiateEPSS 2.5%CVE-2018-19000LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.EPSS 2.5%CVE-2026-28411CRITICALWeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`EPSS 2.3%CVE-2020-6091CRITICALAn exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MEPSS 2.3%CVE-2019-13526Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker toEPSS 2.3%CVE-2019-5165HIGHAn exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A speciallEPSS 2.1%CVE-2025-22462CRITICALAn authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows EPSS 2.1%CVE-2025-27129CRITICALAn authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted EPSS 2.1%CVE-2018-4852A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to theEPSS 2.1%CVE-2024-9933CRITICALWatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value CheckEPSS 2.0%CVE-2024-28200CRITICALN-central Authentication BypassEPSS 1.9%CVE-2022-1681HIGHAuthentication Bypass Using an Alternate Path or Channel in requarks/wikiEPSS 1.9%CVE-2025-0364CRITICALBigAntSoft BigAnt Server Account Registration Bypass to File Upload RCEEPSS 1.9%CVE-2023-2834CRITICALBookIt <= 2.3.7 - Authentication BypassEPSS 1.9%CVE-2022-24047MEDIUMThis vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication EPSS 1.9%