Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2025-59292HIGHAzure Compute Gallery Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-33329HIGHFileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence OracleEPSS 0.4%CVE-2024-11838HIGHLocal File InclusionEPSS 0.4%CVE-2026-48720HIGHWarp: SSH remote output can lead to local file overwrite and persistenceEPSS 0.4%CVE-2025-25478MEDIUMThe account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads toEPSS 0.4%CVE-2025-12137MEDIUMImport WP – Export and Import CSV and XML files to WordPress <= 2.14.16 - Authenticated (Admin+) Arbitrary File ReadEPSS 0.4%CVE-2026-35465HIGHSecureDrop Client has path injection in read_gzip_header_filename()EPSS 0.4%CVE-2026-88899CRITICALknowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory HeaderEPSS 0.4%CVE-2026-48520MEDIUMLangflow: Unauthenticated Shareable Playground arbitrary local or S3 file readEPSS 0.4%CVE-2026-65941HIGHWhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.EPSS 0.4%CVE-2024-10210HIGHPath traversal in APROL Web PortalEPSS 0.4%CVE-2024-12357MEDIUMSourceCodester Best House Rental Management System index.php file inclusionEPSS 0.4%CVE-2026-25964MEDIUMTandoor Recipes Affected by Authenticated Local File Disclosure (LFD) via Recipe Import leads to Arbitrary File ReadEPSS 0.4%CVE-2025-1730MEDIUMSimple Download Counter <= 2.0 - Authenticated (Author+) Arbitrary File ReadEPSS 0.4%CVE-2026-32749HIGHSiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file writeEPSS 0.4%CVE-2026-75602MEDIUMOpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolEPSS 0.4%CVE-2026-33645HIGHFireshare has Path Traversal Arbitrary File Write in `/api/uploadChunked`EPSS 0.4%CVE-2026-53632MEDIUMNTLMv2 hash disclosure via UNC path handling on WindowsEPSS 0.4%CVE-2026-50148CRITICALMetabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File WriteEPSS 0.4%CVE-2026-32949HIGHSQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQLEPSS 0.4%