Weaknesses of type CWE-639

2,490 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2026-2347CRITICALIDOR in Akıllı Ticaret's E-Commerce PackEPSS 0.4%CVE-2026-32300HIGHConnect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User InformationEPSS 0.4%CVE-2026-35147HIGHHCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.EPSS 0.4%CVE-2026-55234HIGHWekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)EPSS 0.4%CVE-2026-1989HIGHIDOR in PAVO Inc.'s PAVO PayEPSS 0.4%CVE-2026-33702HIGHChamilo LMS has an Insecure Direct Object Reference (IDOR)EPSS 0.4%CVE-2026-42999MEDIUMAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raEPSS 0.4%CVE-2024-7473HIGHIDOR Vulnerability in lunary-ai/lunaryEPSS 0.4%CVE-2026-6612MEDIUMTransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution authorizationEPSS 0.4%CVE-2026-71404HIGHRancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRoleEPSS 0.4%CVE-2023-41796MEDIUMWordPress Sunshine Photo Cart Plugin < 3.0.0 is vulnerable to Insecure Direct Object References (IDOR)EPSS 0.4%CVE-2025-5948CRITICALService Finder Bookings <= 6.0 - Unauthenticated Privilege Escalation via claim_businessEPSS 0.4%CVE-2026-28696HIGHCraft affected by IDOR via GraphQL @parseRefsEPSS 0.4%CVE-2026-69190MEDIUMGraylog: Manager-to-Owner privilege escalation on saved searches and dashboardsEPSS 0.4%CVE-2026-16105MEDIUMKeycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpointsEPSS 0.4%CVE-2026-92567HIGHTDuck survey form through 5.0 Unauthorized Data ModificationEPSS 0.4%CVE-2026-12418MEDIUMUser Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' ParameterEPSS 0.4%CVE-2026-86113HIGHBookWyrm through 0.9.1 Insecure Direct Object Reference in edit-readthrough Allows Tampering with Other Users' Reading RecordsEPSS 0.4%CVE-2026-6802MEDIUMEasy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' ParameterEPSS 0.4%CVE-2025-34436HIGHAVideo < 20.1 IDOR Arbitrary File UploadEPSS 0.4%