Weaknesses of type CWE-639

2,490 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2021-41111MEDIUMAuthorization Bypass Through User-Controlled Key in RundeckEPSS 0.6%CVE-2026-46453MEDIUMApache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operationEPSS 0.6%CVE-2026-59733HIGHrclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositoriesEPSS 0.6%CVE-2026-48206MEDIUMApache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentialsEPSS 0.6%CVE-2026-49228HIGHVvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' productsEPSS 0.6%CVE-2026-72863CRITICALDokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker hostEPSS 0.6%CVE-2026-62283CRITICALNezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership checkEPSS 0.6%CVE-2026-49221HIGHVvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assetsEPSS 0.6%CVE-2023-1911MEDIUMBlocksy Companion < 1.8.82 - Subscriber+ Draft Post AccessEPSS 0.5%CVE-2026-20342HIGHCisco Secure Firewall Management Center Software Low Privileged Arbitrary File Download VulnerabilityEPSS 0.5%CVE-2025-31833MEDIUMWordPress JobBoard Job listing plugin Plugin <= 1.2.8 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.5%CVE-2024-11167CRITICALImproper Access Control in danny-avila/librechatEPSS 0.5%CVE-2026-51925HIGHA Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code vEPSS 0.5%CVE-2026-7201HIGHCWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress SitefinityEPSS 0.5%CVE-2023-32799MEDIUMWordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.3 is vulnerable to Insecure Direct Object References (IDOR)EPSS 0.5%CVE-2024-24312HIGHSQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the ModelEPSS 0.5%CVE-2026-11896MEDIUMMy Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' ParameterEPSS 0.5%CVE-2024-10855HIGHImage Optimizer, Resizer and CDN – Sirv <= 7.3.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Option DeletionEPSS 0.5%CVE-2024-53617MEDIUMA Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file EPSS 0.5%CVE-2026-9152CRITICALUnauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant Data Exfiltration and Index DestructionEPSS 0.5%