Weaknesses of type CWE-288

675 results

Controle de acesso inadequado

A aplicação não valida corretamente quem pode acessar um recurso, função ou dado sensível. O atacante consegue contornar as verificações de autenticação ou autorização e executa ações não permitidas (ler dados de outro usuário, modificar configurações críticas, etc.). Essa é uma das falhas mais comuns e perigosas em desenvolvimento web e APIs.

Example

Uma API de banco de dados retorna dados do usuário ID 123 quando você requisita `/api/users/123`, mas não verifica se você é realmente o dono desse perfil ou um admin. Um atacante muda o ID na URL para `/api/users/456` e acessa dados de outro cliente sem nenhuma barreira.

How to mitigate

Sempre valide a identidade do usuário (autenticação) e depois confirme explicitamente se ele tem permissão para aquele recurso (autorização). Use tokens seguros, implemente controle de acesso baseado em papéis ou atributos, e teste cada endpoint com usuários diferentes para garantir que um não acessa dados do outro.

CVE-2026-83527HIGHAn Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain adminiEPSS 1.5%CVE-2024-51464MEDIUMIBM i authentication bypassEPSS 1.4%CVE-2020-4050LOWset-screen-option filter misuse by plugins leading to privilege escalation in WordPressEPSS 1.4%CVE-2021-32967Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or aEPSS 1.4%CVE-2023-2546HIGHWP User Switch <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass via CookieEPSS 1.4%CVE-2019-9510MEDIUMMicrosoft Windows RDP can bypass the Windows lock screenEPSS 1.3%CVE-2021-3849CRITICALAn authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System ManaEPSS 1.3%CVE-2025-61733HIGHApache Kylin: Authentication bypassEPSS 1.3%CVE-2023-2499CRITICALRegistrationMagic <= 5.2.1.0 - Authentication BypassEPSS 1.3%CVE-2024-11028CRITICALMultiManager WP – Manage All Your WordPress Sites Easily <= 1.0.5 - Authentication Bypass via User ImpersonationEPSS 1.3%CVE-2021-3897CRITICALAn authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System MaEPSS 1.3%CVE-2021-26634CRITICALMaxboard multiple vulnerabilitiesEPSS 1.3%CVE-2018-10841MEDIUMglusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with EPSS 1.3%CVE-2021-21952CRITICALAn authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy EPSS 1.3%CVE-2026-3324HIGHAuthentication BypassEPSS 1.3%CVE-2023-2733CRITICALMStore API <= 3.9.0 - Authentication BypassEPSS 1.2%CVE-2022-34372CRITICALDell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attackerEPSS 1.2%CVE-2024-11349CRITICALAdForest <= 5.1.6 - Authentication BypassEPSS 1.2%CVE-2024-10961CRITICALSocial Login <= 5.9.0 - Authentication Bypass via Disqus OAuth providerEPSS 1.2%CVE-2024-10245CRITICALRelais 2FA <= 1.0 - Authentication BypassEPSS 1.2%