Weaknesses of type CWE-639

2,497 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2026-62113MEDIUMWordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-65456MEDIUMWordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-28736MEDIUMFocalboard IDOR in file content endpoint allows cross-user file access (unsupported product, no fix)EPSS 0.3%CVE-2026-74930MEDIUMWP Project Manager 2.2.0 - 4.0.6 - Subscriber+ User Activity Feed Disclosure via IDOREPSS 0.3%CVE-2026-54015MEDIUMOpen WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletionEPSS 0.3%CVE-2026-1947HIGHNEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_idEPSS 0.3%CVE-2025-24969MEDIUMiTop portal user can see any other contact's pictureEPSS 0.3%CVE-2025-62252MEDIUMInsecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and LiferayEPSS 0.3%CVE-2025-63513MEDIUMkishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functiEPSS 0.3%CVE-2026-2366LOWKeycloak: keycloak: information disclosure via authorization bypass in admin apiEPSS 0.3%CVE-2026-82271HIGHR2R Missing Ownership Check Allows Modifying Other Users' ConversationsEPSS 0.3%CVE-2026-79917MEDIUMMaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversationEPSS 0.3%CVE-2025-25777HIGHInsecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulaEPSS 0.3%CVE-2025-9081LOWIDOR in board file download allows any user to download any file by UUIDEPSS 0.3%CVE-2026-24379MEDIUMWordPress WP Job Portal plugin <= 2.4.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-81846LOWrunZero MCP 'Findings summaries' Data LeakEPSS 0.3%CVE-2025-15370MEDIUMShield Security <= 21.0.9 - Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google AuthenticatorEPSS 0.3%CVE-2025-27433MEDIUMBroken Access Control vulnerabilities in SAP S/4HANA (Manage Bank Statements)EPSS 0.3%CVE-2024-13887MEDIUMBusiness Directory Plugin - Easy Listing Directories for WordPress <= 6.4.14 - Insecure Direct Object Reference to Listing Arbitrary Image AdditionEPSS 0.3%CVE-2026-100534LOWOpenClaw before 2026.8.1 Session Cancellation Authorization BypassEPSS 0.3%