Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-55002HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-39907HIGHUnisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via WCF SOAPEPSS 0.6%CVE-2025-52465HIGHGeoServer has an arbitrary file write vulnerability in its Master Password Dump PageEPSS 0.6%CVE-2026-14480HIGHOpenPLC v3 External Control of File Name or PathEPSS 0.6%CVE-2026-55477HIGHAuthenticated Arbitrary File Write via Database Import and Xray Log Path ManipulationEPSS 0.6%CVE-2026-65125MEDIUMNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. AEPSS 0.6%CVE-2025-29709CRITICALSourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.EPSS 0.6%CVE-2025-65115HIGHRemote Code Execution Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DMEPSS 0.6%CVE-2026-16338CRITICALDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.6%CVE-2025-29708CRITICALSourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.EPSS 0.6%CVE-2026-17482CRITICALIBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code executionEPSS 0.6%CVE-2026-46383MEDIUMMicrosoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`EPSS 0.6%CVE-2026-58293HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-37295HIGHAimeos Core remote code execution in web server contextEPSS 0.6%CVE-2024-2150MEDIUMSourceCodester Insurance Management System file inclusionEPSS 0.6%CVE-2025-3812HIGHWPBot Pro Wordpress Chatbot <= 13.6.2 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.6%CVE-2026-8095HIGHFrontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.6%CVE-2026-49360HIGHRecce server has unauthenticated SQL execution that allows local file read/write through DuckDBEPSS 0.6%CVE-2026-64679HIGHAtlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/CreationEPSS 0.6%CVE-2026-40086MEDIUMRembg has a Path Traversal via Custom Model LoadingEPSS 0.6%