Weaknesses of type CWE-441

157 results

Deputado Confuso (Proxy ou Intermediário Não Intencional)

Quando um componente intermediário (servidor, API, função, etc.) executa ações em nome de um cliente sem validar adequadamente quem realmente autorizou aquela ação, um atacante consegue explorar a confiança já estabelecida entre esse intermediário e outros sistemas. O intermediário acaba agindo como 'procurador involuntário' do atacante, realizando operações que o sistema final nunca autorizaria se a requisição viesse diretamente do atacante.

Example

Um servidor de cache proxy que aceita requisições GET de qualquer origem e as repassa a um serviço interno sem verificar se o cliente original deveria ter acesso àqueles dados. Um atacante faz o proxy buscar informações sensíveis do servidor interno e devolver para si, usando a confiança que o servidor interno tem no proxy.

How to mitigate

Valide a identidade e autorização do cliente original antes de repassar requisições para sistemas internos; use tokens ou assinaturas criptográficas que viagem junto com a requisição; implemente listas de origem segura (whitelist) rigorosas e autenticação mútua entre componentes intermediários e backends.

CVE-2026-86115MEDIUMSim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a User-Supplied /api/ PathEPSS 0.3%CVE-2026-12879MEDIUMCross-Tenant Data Exfiltration in Apigee via BigQuery Confused DeputyEPSS 0.3%CVE-2026-50022MEDIUMMetacat acts as unintended proxy to backend Apache SOLR engineEPSS 0.3%CVE-2025-68944MEDIUMGitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.EPSS 0.3%CVE-2026-24470HIGHSkipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalNameEPSS 0.3%CVE-2026-73424MEDIUMAstro: Unauthenticated path override in the @astrojs/vercel ISR functionEPSS 0.3%CVE-2026-81303MEDIUMHawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnameEPSS 0.3%CVE-2026-72640MEDIUMUnintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret DisclosureEPSS 0.3%CVE-2026-87442LOWConfused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%CVE-2022-39349MEDIUMTasks.org vulnerable to data exfiltration by malicous app or adbEPSS 0.3%CVE-2026-87453MEDIUMConfused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2025-64125CRITICALNuvation Energy nCloud Client-to-Client CommunicationEPSS 0.3%CVE-2026-53513CRITICALBetter Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationEPSS 0.2%CVE-2026-77348HIGHWallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`EPSS 0.2%CVE-2026-16158HIGH@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collisionEPSS 0.2%CVE-2026-49821HIGHFission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltrationEPSS 0.2%CVE-2026-50169MEDIUMAngular Service Worker Policy-Bypass & Credential-Stripping VulnerabilitiesEPSS 0.2%CVE-2026-3160MEDIUMUnintended Proxy or Intermediary ('Confused Deputy') in GitLabEPSS 0.2%CVE-2026-48522MEDIUMPyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemesEPSS 0.2%CVE-2026-73266HIGHClusterclaims-controller: confused deputy: tenant-controlled clusterclaim labels propagated to managedcluster, enabling cross-tenant managedclusterset joinEPSS 0.2%