Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-40086MEDIUMRembg has a Path Traversal via Custom Model LoadingEPSS 0.6%CVE-2022-42891HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service usiEPSS 0.6%CVE-2022-42893HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service usiEPSS 0.6%CVE-2026-9559CRITICALA path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign importsEPSS 0.6%CVE-2026-17431MEDIUMPDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_forEPSS 0.6%CVE-2026-10816HIGHArbitrary File Read (Unauthenticated)EPSS 0.6%CVE-2026-59683CRITICALOpenRGB: local and remote system compromise via arbitrary file write using attacker controlled stringsEPSS 0.6%CVE-2026-90817CRITICALAn unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in whicEPSS 0.6%CVE-2026-59819LOWLiteLLM: Local file read via request-supplied OIDC file referencesEPSS 0.6%CVE-2026-48162CRITICALWazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh managerEPSS 0.6%CVE-2026-84374HIGHLaravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathEPSS 0.6%CVE-2025-65473CRITICALAn arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with AdministraEPSS 0.6%CVE-2024-57394HIGHThe quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to EPSS 0.6%CVE-2026-90946HIGHDeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocketEPSS 0.6%CVE-2024-1603HIGHconfirmedEPSS 0.6%CVE-2025-10134CRITICALGoza - Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File DeletionEPSS 0.6%CVE-2026-35174CRITICALChyrp Lite has a Path Traversal to Remote Code ExecutionEPSS 0.6%CVE-2025-5393CRITICALAlone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary File DeletionEPSS 0.6%CVE-2026-40370HIGHSQL Server Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-33117CRITICALIBM QRadar SIEM command executionEPSS 0.6%