Weaknesses of type CWE-639

2,490 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2026-5234MEDIUMLatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice IDEPSS 0.6%CVE-2024-9097LOWIDOREPSS 0.6%CVE-2026-69857HIGHAzure Cosmos DB Spoofing VulnerabilityEPSS 0.6%CVE-2024-53406HIGHEspressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuEPSS 0.6%CVE-2026-1992HIGHExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin InstallationEPSS 0.6%CVE-2026-46585HIGHApache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search queryEPSS 0.6%CVE-2026-17567MEDIUMFluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' ParameterEPSS 0.6%CVE-2025-45968CRITICALAn issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contaiEPSS 0.6%CVE-2022-36284MEDIUMWordPress Affiliate For WooCommerce premium plugin <= 4.7.0 - Authenticated IDOR vulnerability leading to PayPal email changeEPSS 0.6%CVE-2026-72724MEDIUMDiscourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID MismatchEPSS 0.6%CVE-2026-61574HIGHauthentik RAC: access any endpoint via an unrelated applicationEPSS 0.6%CVE-2026-33511HIGHpyload-ng: Authentication Bypass via Host Header Injection in ClickNLoadEPSS 0.6%CVE-2026-57510HIGHSuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPCEPSS 0.6%CVE-2024-2543MEDIUMPlugin Permalink <= 2.4.3.1 - Missing Authorization via get_uri_editorEPSS 0.6%CVE-2024-2472CRITICALLatePoint Plugin <= 4.9.9 - Missing Authorization and Sensitive Information Exposure via IDOREPSS 0.6%CVE-2024-40395MEDIUMAn Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardlessEPSS 0.6%CVE-2026-68076MEDIUMApache Airflow: Connections test API: team-scope guard bypass resolves another team's environment ConnectionEPSS 0.6%CVE-2026-73239MEDIUMApache Allura: Missing permission checks IDOREPSS 0.6%CVE-2018-17455HIGHAn issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sEPSS 0.6%CVE-2025-1607MEDIUMSourceCodester Best Employee Management System salary_slip.php authorizationEPSS 0.6%