Weaknesses of type CWE-610

96 results

Controle de acesso inadequado

A aplicação não valida corretamente se um usuário tem permissão para acessar um recurso, operação ou dado específico. O resultado é que usuários não autorizados conseguem contornar as verificações de autenticação ou autorização e acessar informações sensíveis ou executar ações que não deveriam.

Example

Um sistema web que permite visualizar perfil de qualquer usuário apenas mudando o ID na URL (exemplo: /perfil/123 para /perfil/124), sem verificar se o usuário logado é o dono daquele perfil. Um atacante enumera IDs e extrai dados pessoais alheios.

How to mitigate

Sempre validar, no servidor, se o usuário autenticado tem permissão explícita para o recurso solicitado — nunca confiar apenas em parâmetros do cliente. Use modelos de autorização bem definidos (RBAC, ABAC) e testes de acesso em todas as rotas sensíveis.

CVE-2026-57301HIGHJenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attaEPSS 0.6%CVE-2025-11140MEDIUMBjskzy Zhiyou ERP com.artery.richclient.RichClientService openForm xml external entity referenceEPSS 0.6%CVE-2022-43423MEDIUMJenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that doesEPSS 0.6%CVE-2024-24818MEDIUMEspoCRM weakness in "Forgot password"EPSS 0.6%CVE-2018-12475MEDIUMobs-service-download_files allows downloading from localhost or intranet hostsEPSS 0.6%CVE-2026-0522HIGHLocal File Inclusion in the File Upload/Download ProcessEPSS 0.6%CVE-2025-7523MEDIUMJinher OA DelTemp.aspx xml external entity referenceEPSS 0.6%CVE-2023-37856MEDIUMPHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsEPSS 0.6%CVE-2023-37855MEDIUMPHOENIX CONTACT: Unauthorized read-access of root filesystem in WP 6xxx Web panelsEPSS 0.6%CVE-2025-10091MEDIUMJinher OA XML Type xml external entity referenceEPSS 0.5%CVE-2025-10092MEDIUMJinher OA XML Type xml external entity referenceEPSS 0.5%CVE-2025-10816MEDIUMJinher OA XML text xml external entity referenceEPSS 0.5%CVE-2025-11341MEDIUMJinher OA type xml external entity referenceEPSS 0.5%CVE-2026-15583HIGHSSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL headerEPSS 0.5%CVE-2025-7824MEDIUMJinher OA XmlHttp.aspx xml external entity referenceEPSS 0.5%CVE-2025-7823MEDIUMJinher OA ProjectScheduleDelete.aspx xml external entity referenceEPSS 0.5%CVE-2024-32980CRITICALSpin contains a potential network sandbox escape for specifically configured Spin applicationsEPSS 0.5%CVE-2026-47357CRITICALTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan eEPSS 0.5%CVE-2026-47358CRITICALTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when EPSS 0.5%CVE-2015-10142MEDIUMSitecore XP < 8.0 and CMS < 7.2 and < 7.5 File Read via Known PathEPSS 0.5%