Weaknesses of type CWE-610

96 results

Controle de acesso inadequado

A aplicação não valida corretamente se um usuário tem permissão para acessar um recurso, operação ou dado específico. O resultado é que usuários não autorizados conseguem contornar as verificações de autenticação ou autorização e acessar informações sensíveis ou executar ações que não deveriam.

Example

Um sistema web que permite visualizar perfil de qualquer usuário apenas mudando o ID na URL (exemplo: /perfil/123 para /perfil/124), sem verificar se o usuário logado é o dono daquele perfil. Um atacante enumera IDs e extrai dados pessoais alheios.

How to mitigate

Sempre validar, no servidor, se o usuário autenticado tem permissão explícita para o recurso solicitado — nunca confiar apenas em parâmetros do cliente. Use modelos de autorização bem definidos (RBAC, ABAC) e testes de acesso em todas as rotas sensíveis.

CVE-2023-4089LOWWAGO: Multiple products vulnerable to local file inclusionEPSS 0.5%CVE-2025-9065HIGHRockwell Automation ThinManager® Server-Side Request Forgery VulnerabilityEPSS 0.5%CVE-2026-19032MEDIUMjackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.PathEPSS 0.5%CVE-2023-38046MEDIUMPAN-OS: Read System Files and Resources During Configuration CommitEPSS 0.5%CVE-2026-78966MEDIUMExternally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a EPSS 0.5%CVE-2022-23439MEDIUMA externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafteEPSS 0.4%CVE-2026-79256HIGHExternally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromisEPSS 0.4%CVE-2026-55389HIGHdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`EPSS 0.4%CVE-2025-5877MEDIUMFengoffice Feng Office Document Upload ApplicationDataObject.class.php xml external entity referenceEPSS 0.4%CVE-2025-2875HIGHCWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality wheEPSS 0.4%CVE-2025-11035MEDIUMJinher OA text xml external entity referenceEPSS 0.4%CVE-2026-32008HIGHOpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation GuardEPSS 0.4%CVE-2026-12788MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity referenceEPSS 0.4%CVE-2024-6717HIGHNomad Vulnerable to Allocation Directory Path Escape Through Archive UnpackingEPSS 0.4%CVE-2025-1225MEDIUMywoa WXCallBack Interface XMLParse.java extract xml external entity referenceEPSS 0.4%CVE-2024-28962MEDIUMDell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulneraEPSS 0.4%CVE-2024-42168HIGHHCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerabilityEPSS 0.4%CVE-2023-22616HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driEPSS 0.4%CVE-2026-62960HIGHGit for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on WindowsEPSS 0.4%CVE-2026-55390HIGHArbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gateEPSS 0.4%