Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2025-12915HIGH70mai X200 Init Script file inclusionEPSS 0.4%CVE-2025-27147HIGHGLPI Inventory plugin has Improper Access Control VulnerabilityEPSS 0.4%CVE-2024-9142CRITICALLocal File Inclusion (LFI) in Olgu Computer Systems' e-BelediyeEPSS 0.4%CVE-2026-53940HIGHConda: Entry-point path traversal in noarch:python install (arbitrary file write) — canonical Python implementationEPSS 0.4%CVE-2025-0630MEDIUMWestern Telematic Inc NPS Series, DSM Series, CPM Series External Control of File Name or PathEPSS 0.4%CVE-2025-25761HIGHHkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.EPSS 0.4%CVE-2025-20269MEDIUMCisco Evolved Programmable Network Manager and Prime Infrastructure Arbitrary File Download VulnerabilityEPSS 0.4%CVE-2026-72842CRITICALOpenWrt luci-app-lxc ACL Inconsistency Authentication BypassEPSS 0.4%CVE-2026-76553MEDIUMWP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path TraversalEPSS 0.4%CVE-2025-26684MEDIUMMicrosoft Defender Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-36506MEDIUMExternal control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a speEPSS 0.4%CVE-2026-15540MEDIUMSourceCodester Online Book Store System Administrative index.php php file inclusionEPSS 0.4%CVE-2026-44019HIGHDocling Core has insufficient validation of image reference URIsEPSS 0.4%CVE-2026-55700HIGHpnpm: stage download writes outside destination via manifest version traversalEPSS 0.4%CVE-2026-19011MEDIUMTinyAGI agents.ts buildSystemPrompt file inclusionEPSS 0.4%CVE-2023-47147MEDIUMIBM Secure Proxy file manipulationEPSS 0.4%CVE-2026-76158CRITICALDatiphy Data Management Center - External Control of File Name or PathEPSS 0.4%CVE-2026-18127HIGHExternal control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full wrEPSS 0.4%CVE-2025-12654LOWMigration, Backup, Staging – WPvivid Backup & Migration <= 0.9.120 - Authenticated (Admin+) Arbitrary Directory CreationEPSS 0.4%CVE-2026-23529HIGHArbitrary File Read in Google BigQuery Sink connectorEPSS 0.4%