Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-67920HIGHAn issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWEPSS 0.7%CVE-2024-7497MEDIUMitsourcecode Airline Reservation System index.php file inclusionEPSS 0.7%CVE-2024-7496MEDIUMitsourcecode Airline Reservation System index.php file inclusionEPSS 0.7%CVE-2023-3256HIGHAdvantech R-SeeNet External Control of File Name or PathEPSS 0.6%CVE-2025-9048HIGHWptobe-memberships <= 3.4.2 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.6%CVE-2025-64712CRITICALUnstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File WriteEPSS 0.6%CVE-2024-1243CRITICALRemote code execution and local privilege escalation in Wazuh Windows agent via NetNTLMv2 hash theftEPSS 0.6%CVE-2024-55372CRITICALWallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by EPSS 0.6%CVE-2022-45213MEDIUMperfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.EPSS 0.6%CVE-2025-0109MEDIUMPAN-OS: Unauthenticated File Deletion Vulnerability on the Management Web InterfaceEPSS 0.6%CVE-2025-13322HIGHWP AUDIO GALLERY <= 2.0 - Authenticated (Subscriber+) Arbitrary File Deletion via 'audio_upload' ParameterEPSS 0.6%CVE-2025-8422HIGHPropovoice <= 1.7.6.7 - Unauthenticated Arbitrary File ReadEPSS 0.6%CVE-2023-36634MEDIUMAn incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.EPSS 0.6%CVE-2025-53912CRITICALAn arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTEPSS 0.6%CVE-2024-10834CRITICALArbitrary File Write in eosphoros-ai/db-gptEPSS 0.6%CVE-2026-42845HIGHGrav: Anonymous Page Content Overwrite via Form File Upload filename OverrideEPSS 0.6%CVE-2026-35593MEDIUMTrilium Notes has Local File Inclusion via upload modified file API endpointEPSS 0.6%CVE-2026-40421MEDIUMMicrosoft Word Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-55371CRITICALWallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploEPSS 0.6%CVE-2025-10058HIGHWP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.6%