Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-57898CRITICALIn Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to EPSS 0.7%CVE-2025-0211MEDIUMCampcodes School Faculty Scheduling System index.php file inclusionEPSS 0.7%CVE-2025-4602MEDIUMeMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File ReadEPSS 0.7%CVE-2026-46402HIGHMicrosoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directoryEPSS 0.7%CVE-2025-47956MEDIUMWindows Security App Spoofing VulnerabilityEPSS 0.7%CVE-2022-42734HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service usiEPSS 0.7%CVE-2024-5986CRITICALRemote Arbitrary File Write with Arbitrary Data in h2oai/h2o-3EPSS 0.7%CVE-2026-30276CRITICALAn arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via theEPSS 0.7%CVE-2022-42732HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service usiEPSS 0.7%CVE-2024-38173MEDIUMMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-22178MEDIUMA file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.0EPSS 0.7%CVE-2024-21870MEDIUMA file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. AEPSS 0.7%CVE-2022-31739HIGHWhen downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-EPSS 0.7%CVE-2026-5821HIGHImage Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion via Post Meta Field InjectionEPSS 0.7%CVE-2025-66292HIGHDPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interfaceEPSS 0.7%CVE-2026-85684HIGHmarker through 2.0.0 Path Traversal via upload filenameEPSS 0.7%CVE-2024-39904HIGHCode Execution Vulnerability via Local File Path Traversal in VnoteEPSS 0.7%CVE-2026-16139HIGHArbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code executionEPSS 0.7%CVE-2026-66324MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.7%CVE-2026-41107HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.7%