Weaknesses of type CWE-639

2,502 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2026-52841LOWEasy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google syncEPSS 0.2%CVE-2026-10780MEDIUMStatic Block <= 2.2 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode 'id' AttributeEPSS 0.2%CVE-2024-41254MEDIUMAn issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowinEPSS 0.2%CVE-2026-14212MEDIUMAmelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOREPSS 0.2%CVE-2026-80342MEDIUMPayment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hijacking via Unvalidated PayPal Order IDEPSS 0.2%CVE-2026-78581MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in KibanaEPSS 0.2%CVE-2026-24776MEDIUMOpenProject has an IDOR on MeetingAgendaItems allows cross-project meeting agenda item transferEPSS 0.2%CVE-2025-67594MEDIUMWordPress Thim Elementor Kit plugin <= 1.3.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-48783MEDIUMPostiz has an unauthenticated billing-enforcement bypass via /public/modify-subscriptionEPSS 0.2%CVE-2026-11142MEDIUMInsufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via EPSS 0.2%CVE-2025-10912MEDIUMIDOR in saastech.io's TemizlikYoldaEPSS 0.2%CVE-2024-22439MEDIUMCertain HPE FlexNetwork and FlexFabric Switches, Remote Authentication BypassEPSS 0.2%CVE-2026-17627MEDIUMLangflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpointEPSS 0.2%CVE-2026-55411MEDIUMToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/decrypt — any authenticated user can decrypt any organization's data-source secretsEPSS 0.2%CVE-2025-7733MEDIUMWP JobHunt <= 7.7 - Authenticated (Candidate+) Insecure Direct Object ReferenceEPSS 0.2%CVE-2025-12126MEDIUMThe Total Book Project <= 1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Book ManipulationEPSS 0.2%CVE-2026-1753MEDIUMGutena Forms < 1.6.1 - Contributor+ Arbitrary Limited Options UpdateEPSS 0.2%CVE-2026-2230MEDIUMBooking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings ModificationEPSS 0.2%CVE-2026-22489MEDIUMWordPress Image Slider Slideshow plugin <= 1.8 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-77766MEDIUMDirectorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure via REST Orders EndpointEPSS 0.2%