Weaknesses of type CWE-639

2,490 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2024-5977MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post ActionsEPSS 0.4%CVE-2023-47191MEDIUMWordPress Youzify Plugin <= 1.2.2 is vulnerable to Insecure Direct Object References (IDOR)EPSS 0.4%CVE-2026-45750CRITICALTermix Vulnerable to Arbitrary Command Execution in File ManagerEPSS 0.4%CVE-2026-6810MEDIUMBooking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar TakeoverEPSS 0.4%CVE-2026-3306MEDIUMImproper authorization in GitHub Projects allows modification of issue and pull request metadata without repository write accessEPSS 0.4%CVE-2026-32589HIGHMirror-registry: quay: insecure direct object reference in blobuploadEPSS 0.4%CVE-2026-40480HIGHChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`EPSS 0.4%CVE-2026-42276MEDIUMOnyx: IDOR in /chat/stop-chat-session allows any authenticated user to interrupt other users chat sessionsEPSS 0.4%CVE-2026-55881HIGHOpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpointEPSS 0.4%CVE-2024-13372MEDIUMWP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Arbitrary Resume DownloadEPSS 0.4%CVE-2024-11285CRITICALWP JobHunt <= 7.1 - Unauthenticated Privilege Escalation via Email Update/Account TakeoverEPSS 0.4%CVE-2025-49952MEDIUMWordPress Houzez theme <= 4.2.5 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.4%CVE-2026-52826MEDIUMKimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate ManipulationEPSS 0.4%CVE-2026-52821MEDIUMKimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized ProjectsEPSS 0.4%CVE-2026-50141HIGHWoodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonationEPSS 0.4%CVE-2026-82395MEDIUMSulu: Media move/update authorization bypass (IDOR)EPSS 0.4%CVE-2023-7286MEDIUMACF Quick Edit Fields <= 3.2.2 - Authenticated (Contributor+) Insecure Direct Object ReferenceEPSS 0.4%CVE-2026-56069HIGHWordPress Toolset Forms plugin <= 2.6.24 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.4%CVE-2026-92716HIGHShuffle through 2.2.1 API Key Reset Cross-Tenant Privilege EscalationEPSS 0.4%CVE-2026-2347CRITICALIDOR in Akıllı Ticaret's E-Commerce PackEPSS 0.4%