Weaknesses of type CWE-639

2,500 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2025-13003HIGHIDOR in Aksis Computer's AxOnboardEPSS 0.2%CVE-2026-76089HIGHFormie: Missing authorization on sent notification resend modal exposes submission PIIEPSS 0.2%CVE-2025-12040MEDIUMWishlist for WooCommerce <= 1.1.3 - Insecure Direct Object Reference to Unauthenticated Wishlist ManipulationEPSS 0.2%CVE-2026-24634MEDIUMWordPress Ultimate Reviews plugin <= 3.2.16 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-53536MEDIUMActivepieces: Cross-tenant file download via missing JWT audience check on step-files signed URLEPSS 0.2%CVE-2023-40200MEDIUMWordPress WP Logo Showcase Responsive Slider and Carousel plugin <= 3.6 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-97721MEDIUMSanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsContentAdminController authorizationEPSS 0.2%CVE-2026-52812HIGHGogs: LFS dedupe path leaks private repo content across tenantsEPSS 0.2%CVE-2026-92436MEDIUMMailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOREPSS 0.2%CVE-2024-29024MEDIUMJumpServer Direct Object Reference (IDOR) Vulnerability in File Manager Bulk Transfer FunctionalityEPSS 0.2%CVE-2026-22407MEDIUMWordPress Roam theme <= 2.1.1 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-23843HIGHteklifolustur_app's IDOR vulnerability allows unauthorized access to other users' offersEPSS 0.2%CVE-2026-22404MEDIUMWordPress Innovio theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-22409MEDIUMWordPress Justicia theme <= 1.2 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-22406MEDIUMWordPress Overton theme <= 1.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-22411MEDIUMWordPress Dolcino theme <= 1.6 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2023-36331HIGHIncorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via maEPSS 0.2%CVE-2026-1883MEDIUMWicked Folders <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder DeletionEPSS 0.2%CVE-2025-64706MEDIUMTypebot IDOR Vulnerability: Unauthorized API Token Deletion and ExposureEPSS 0.2%CVE-2026-100609HIGHFlowise through 3.1.4 Insecure Direct Object Reference via CredentialEPSS 0.2%