Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-59682HIGHArbitrary file overwrite and deletion local and remote in OpenRGBEPSS 0.5%CVE-2024-2155MEDIUMSourceCodester Best POS Management System index.php file inclusionEPSS 0.5%CVE-2026-17184CRITICALIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2025-49138MEDIUMHAX CMS vulnerable to Local File Inclusion via saveOutline API Location ParameterEPSS 0.5%CVE-2026-56452HIGHApache MINA SSHD: Path traversal in SCP file receptionEPSS 0.5%CVE-2026-27211CRITICALCloud Hypervisor: Host File Exfiltration via QCOW Backing File AbuseEPSS 0.5%CVE-2026-25628HIGHQdrant affected by arbitrary file write via `/logger` endpointEPSS 0.5%CVE-2026-61462CRITICALmcp-gitlab Path Traversal via job_id ParameterEPSS 0.5%CVE-2025-68155HIGH@vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on DevelopmentEPSS 0.5%CVE-2026-50162MEDIUMoras-go: file store write outside workingDir via symlink traversalEPSS 0.5%CVE-2026-69805HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-20114MEDIUMA vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attackEPSS 0.5%CVE-2025-58158HIGHHarness Affected by Arbitrary File Write in Gitness LFS serverEPSS 0.5%CVE-2026-65802HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-46336HIGHManyfold: Authenticated Path Traversal via File RenameEPSS 0.5%CVE-2026-5809HIGHwpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' ParameterEPSS 0.5%CVE-2024-10672LOWMultiple Page Generator Plugin – MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File DeletionEPSS 0.5%CVE-2026-56705CRITICALAdminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN InjectionEPSS 0.5%CVE-2026-73171HIGHNozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKEPSS 0.5%CVE-2025-64714MEDIUMPrivateBin's template-switching feature allows arbitrary local file inclusion through path traversalEPSS 0.5%