Weaknesses of type CWE-639

2,492 results

Manipulação de identificador para acessar dados de outro usuário

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso solicitado, permitindo que modifique parâmetros (como IDs) para acessar dados alheios. Por exemplo, ao mudar o ID de um pedido na URL de 123 para 456, consegue visualizar pedidos de outros clientes sem controle de acesso real.

Example

Um banco digital permite acessar extratos via URL /extrato?conta_id=5000. Se um usuário muda para conta_id=5001, consegue ver o extrato de outra pessoa apenas porque a aplicação valida apenas autenticação, não autorização específica para aquele recurso.

How to mitigate

Implemente verificação de autorização em cada acesso a recurso: valide se o usuário autenticado de fato possui permissão para aquele ID específico, comparando contra dados da sessão ou banco de dados. Use abstração (ex: 'minha conta' em vez de IDs diretos) e evite expor identificadores sequenciais previsíveis.

CVE-2026-40867HIGHHorilla: Unauthorized Helpdesk Attachment Access via Attachment ID ManipulationEPSS 0.4%CVE-2026-18028LOWMissing authorization check in event quick setup viewEPSS 0.4%CVE-2026-44678HIGHTuist: IDOR in preview deletion API allows cross-tenant deletion of any preview by UUIDEPSS 0.4%CVE-2026-42517HIGHCryptographic Failure Vulnerability in e-Sushrut HMISEPSS 0.4%CVE-2024-55471MEDIUMOqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized useEPSS 0.4%CVE-2026-5750HIGHInsecure direct object reference (IDOR) vulnerability in FullstepEPSS 0.4%CVE-2026-45297MEDIUMCross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatchEPSS 0.4%CVE-2026-77990MEDIUMJoomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1EPSS 0.4%CVE-2026-53911MEDIUMCerebrate primary key mass assignment in CRUD edit operations allows authenticated users to overwrite unrelated recordsEPSS 0.4%CVE-2025-65887MEDIUMA division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) EPSS 0.4%CVE-2026-9712LOWInsecure direct object referenceEPSS 0.4%CVE-2026-54360HIGHMISP sharing group creation mass assignment allows unauthorized takeover of existing sharing groupsEPSS 0.4%CVE-2026-77145HIGHBroken Access Control in extension "Events 2" (events2)EPSS 0.4%CVE-2026-72737CRITICALDokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backupsEPSS 0.4%CVE-2026-10140CRITICALCross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode SubsystemEPSS 0.4%CVE-2026-80254HIGHAuthorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the prodEPSS 0.4%CVE-2024-6410MEDIUMProfileGrid <= 5.8.9 - Authenticated (Subscriber+) Insecure Direct Object ReferenceEPSS 0.4%CVE-2026-33730MEDIUMOpen Source Point of Sale has an IDOR in Password Change (Home)EPSS 0.4%CVE-2026-76397HIGHImproper Access Control in Experiment History through the REST API in Splunk AI ToolkitEPSS 0.4%CVE-2026-13445HIGHLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.4%