Weaknesses of type CWE-639

2,490 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2026-72734HIGHDokploy: Cross-organization authorization bypass in server.remove allows deletion of another organization's server registrationEPSS 0.4%CVE-2026-70557HIGHdiboot-core Authenticated Arbitrary Field Read via loadRelatedData Discloses Password Hashes and SaltsEPSS 0.4%CVE-2024-29181LOW@strapi/plugin-content-manager leaks data via relations via the Admin PanelEPSS 0.4%CVE-2026-72657MEDIUMAuthorization Bypass Through User-Controlled Key in Fleet Server Leading to Information DisclosureEPSS 0.4%CVE-2025-49978MEDIUMWordPress JobSearch plugin < 3.0.6 - Insecure Direct Object References (IDOR) VulnerabilityEPSS 0.4%CVE-2024-12061MEDIUMEvents Addon for Elementor <= 2.2.3 - Authenticated (Contributor+) Post DisclosureEPSS 0.4%CVE-2026-34370MEDIUMChamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notesEPSS 0.4%CVE-2026-2697LOWIndirect Object Reference (IDOR) in Security CenterEPSS 0.4%CVE-2026-47743HIGHShopper: Multiple data integrity and disclosure issues in admin Livewire componentsEPSS 0.4%CVE-2025-55370HIGHIncorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all theEPSS 0.4%CVE-2026-13512MEDIUMDatabend Tenant client_session_manager.rs state_key authorizationEPSS 0.4%CVE-2026-16217MEDIUMguohongze adminset Delivery Deployment Endpoint deli.py authorizationEPSS 0.4%CVE-2026-77368HIGHSeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write to Tenant-Forbidden PathsEPSS 0.4%CVE-2026-78144MEDIUMcode-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorizationEPSS 0.4%CVE-2026-78142MEDIUMcode-projects Barangay Resident Profiling Management System Restore/Delete archived_records.php authorizationEPSS 0.4%CVE-2026-15191MEDIUMmettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorizationEPSS 0.4%CVE-2026-47414HIGHpraisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label edit/delete and issue-label-link IDOREPSS 0.4%CVE-2026-54529MEDIUMSQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`EPSS 0.4%CVE-2026-16214MEDIUMgeex-arts django-jet Dashboard views.py authorizationEPSS 0.4%CVE-2026-83743MEDIUMinvoiceninja Invoice Ninja Vendor Portal Profile Update profile authorizationEPSS 0.4%