Weaknesses of type CWE-610

96 results

Controle de acesso inadequado

A aplicação não valida corretamente se um usuário tem permissão para acessar um recurso, operação ou dado específico. O resultado é que usuários não autorizados conseguem contornar as verificações de autenticação ou autorização e acessar informações sensíveis ou executar ações que não deveriam.

Example

Um sistema web que permite visualizar perfil de qualquer usuário apenas mudando o ID na URL (exemplo: /perfil/123 para /perfil/124), sem verificar se o usuário logado é o dono daquele perfil. Um atacante enumera IDs e extrai dados pessoais alheios.

How to mitigate

Sempre validar, no servidor, se o usuário autenticado tem permissão explícita para o recurso solicitado — nunca confiar apenas em parâmetros do cliente. Use modelos de autorização bem definidos (RBAC, ABAC) e testes de acesso em todas as rotas sensíveis.

CVE-2023-21097HIGHIn toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escEPSS 0.2%CVE-2022-44747LOWLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2022-20515MEDIUMIn onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to aEPSS 0.2%CVE-2022-46868MEDIUMLocal privilege escalation during recovery due to improper soft link handling. The following products are affected: Acronis Cyber Protect HoEPSS 0.2%CVE-2026-28721HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.2%CVE-2026-28722HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.2%CVE-2024-13177MEDIUMSymlink Following in Netskope Client Postinstall ScriptEPSS 0.1%CVE-2025-48963HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (LinuxEPSS 0.1%CVE-2022-20550HIGHIn Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local esEPSS 0.1%CVE-2023-20964HIGHIn multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local EPSS 0.1%CVE-2022-20199MEDIUMIn multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local infoEPSS 0.1%CVE-2024-49722MEDIUMIn showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to EPSS 0.1%CVE-2025-48654HIGHIn onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to lEPSS 0.1%CVE-2024-49728MEDIUMIn generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lEPSS 0.1%CVE-2025-0082MEDIUMIn multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confuseEPSS 0.1%CVE-2026-21810MEDIUMHCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checkingEPSS 0.1%