Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2025-10494HIGHMotors – Car Dealership & Classified Listings Plugin <= 1.4.89 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.5%CVE-2025-13380MEDIUMAI Engine for WordPress: ChatGPT, GPT Content Generator <= 1.0.1 - Authenticated (Contributor+) Arbitrary File ReadEPSS 0.5%CVE-2026-59793HIGHIn JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integrationEPSS 0.5%CVE-2026-33989HIGH@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture toolsEPSS 0.5%CVE-2026-49145HIGHApp::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrcEPSS 0.5%CVE-2021-47871HIGHHestia Control Panel 1.3.2 - Arbitrary File WriteEPSS 0.5%CVE-2026-67429CRITICALFlyto2 Core: Arbitrary file write via image.download (and other file-writing modules)EPSS 0.5%CVE-2026-47357CRITICALTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan eEPSS 0.5%CVE-2026-47358CRITICALTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when EPSS 0.5%CVE-2026-45139MEDIUMCI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operationsEPSS 0.5%CVE-2024-28826HIGHUnrestricted upload and download paths in check_sftpEPSS 0.5%CVE-2024-38040HIGHBUG-000167984 - Portal for ArcGIS has a Local file inclusion (LFI) vulnerabilityEPSS 0.5%CVE-2026-65896HIGHGrav API Plugin before 1.0.10 Path Traversal via moveEPSS 0.5%CVE-2023-43074MEDIUM
Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerEPSS 0.5%CVE-2026-59807HIGHComposio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.tsEPSS 0.5%CVE-2026-77247HIGHMCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parametersEPSS 0.5%CVE-2025-53363MEDIUMDpanel has an arbitrary file read vulnerabilityEPSS 0.5%CVE-2024-22341MEDIUMIBM Watson Query on Cloud Pak for Data information disclosureEPSS 0.5%CVE-2026-73719HIGHAuthenticated Arbitrary File Write Vulnerability leads to Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.5%CVE-2021-4472MEDIUMPython-mistralclient: mistral-dashboard: local file inclusion through the 'create workbook' featureEPSS 0.5%