Weaknesses of type CWE-288

675 results

Controle de acesso inadequado

A aplicação não valida corretamente quem pode acessar um recurso, função ou dado sensível. O atacante consegue contornar as verificações de autenticação ou autorização e executa ações não permitidas (ler dados de outro usuário, modificar configurações críticas, etc.). Essa é uma das falhas mais comuns e perigosas em desenvolvimento web e APIs.

Example

Uma API de banco de dados retorna dados do usuário ID 123 quando você requisita `/api/users/123`, mas não verifica se você é realmente o dono desse perfil ou um admin. Um atacante muda o ID na URL para `/api/users/456` e acessa dados de outro cliente sem nenhuma barreira.

How to mitigate

Sempre valide a identidade do usuário (autenticação) e depois confirme explicitamente se ele tem permissão para aquele recurso (autorização). Use tokens seguros, implemente controle de acesso baseado em papéis ou atributos, e teste cada endpoint com usuários diferentes para garantir que um não acessa dados do outro.

CVE-2022-24047MEDIUMThis vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication EPSS 1.9%CVE-2024-52475CRITICALWordPress Wawp plugin < 3.0.18 - Account Takeover vulnerabilityEPSS 1.9%CVE-2024-47009HIGHPath Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.EPSS 1.7%CVE-2024-9106CRITICALWechat Social login <= 1.3.0 - Authentication BypassEPSS 1.7%CVE-2019-5473An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4EPSS 1.7%CVE-2019-18250In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bEPSS 1.7%CVE-2024-8277CRITICALWooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege EscalationEPSS 1.6%CVE-2023-2704CRITICALBP Social Connect <= 1.5 - Authentication BypassEPSS 1.6%CVE-2023-32002CRITICALThe use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. TEPSS 1.6%CVE-2020-36713CRITICALMStore API <= 2.1.5 - Authentication BypassEPSS 1.6%CVE-2026-44575HIGHNext.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesEPSS 1.6%CVE-2018-8859CRITICALEchelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versionsEPSS 1.6%CVE-2023-1260HIGHKube-apiserver: privescEPSS 1.6%CVE-2021-43985CRITICALmySCADA myPROEPSS 1.5%CVE-2020-36724CRITICALWordable <= 3.1.1 - Authentication BypassEPSS 1.5%CVE-2019-5486A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that coulEPSS 1.5%CVE-2025-21589CRITICALSession Smart Router, Session Smart Conductor, WAN Assurance Router: API Authentication Bypass vulnerabilityEPSS 1.5%CVE-2024-49328CRITICALWordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerabilityEPSS 1.5%CVE-2020-10283HIGHRVD#3317: MAVLink version handshaking allows for an attacker to bypass authenticationEPSS 1.5%CVE-2019-3758HIGHRSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to creaEPSS 1.5%