Weaknesses of type CWE-639

2,498 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2025-50849HIGHCS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickerEPSS 0.3%CVE-2026-84460MEDIUMZammad: Missing Authorization in TagsController#list Allows Cross-Object Tag EnumerationEPSS 0.3%CVE-2026-1558MEDIUMWP Recipe Maker <= 10.3.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' ParameterEPSS 0.3%CVE-2026-87019MEDIUMTanium addressed an improper access controls vulnerability in Comply.EPSS 0.3%CVE-2025-65028MEDIUMRallly Has an IDOR Vulnerability in Vote Update Endpoint Allows Unauthorized Manipulation of Participant VotesEPSS 0.3%CVE-2025-14033MEDIUMilGhera Support System for WooCommerce <= 1.3.0 - Missing Authorization to Unauthenticated Sensitive Information ExposureEPSS 0.3%CVE-2025-8463MEDIUMIDOR in SecHard Information Technologies' SecHardEPSS 0.3%CVE-2025-65032MEDIUMRallly Has an IDOR Vulnerability in Participant Rename Function Allows Unauthorized Modification of Other Users’ NamesEPSS 0.3%CVE-2025-0642MEDIUMHard-coded Credentials in PosCube's AssistEPSS 0.3%CVE-2026-72741HIGHRainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant AccessEPSS 0.3%CVE-2026-77783LOWRank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content DisclosureEPSS 0.3%CVE-2026-14927LOWFluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print RoutesEPSS 0.3%CVE-2026-85291MEDIUMInvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorization CheckEPSS 0.3%CVE-2026-1219MEDIUMMP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information ExposureEPSS 0.3%CVE-2026-14211LOWAmelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOREPSS 0.3%CVE-2026-14197LOWFluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOREPSS 0.3%CVE-2026-14213LOWAmelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOREPSS 0.3%CVE-2026-17570MEDIUMImproper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose EPSS 0.3%CVE-2026-6541MEDIUMUnscoped updates to other playbooks' metric configurationEPSS 0.3%CVE-2026-18200MEDIUMFoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile UpdateEPSS 0.3%