Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-25573HIGHA vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-pEPSS 0.4%CVE-2025-62611HIGHaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL serverEPSS 0.4%CVE-2026-19009MEDIUMTinyAGI Message API Endpoint response.ts collectFiles file inclusionEPSS 0.4%CVE-2025-12656LOWMigration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory DeletionEPSS 0.4%CVE-2026-26359HIGHDell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker wEPSS 0.4%CVE-2026-33949HIGH@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary filesEPSS 0.4%CVE-2025-48783HIGHSoar Cloud HRD Human Resource Management System - External Control of File Name or PathEPSS 0.4%CVE-2026-8118MEDIUMRoyal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File SourceEPSS 0.4%CVE-2025-6237CRITICALPath Traversal and Arbitrary File Deletion in invoke-ai/invokeaiEPSS 0.4%CVE-2025-66257CRITICALUnauthenticated Arbitrary File Deletion (patch_contents.php)EPSS 0.4%CVE-2025-66254HIGHUnauthenticated Arbitrary File Deletion (upgrade_contents.php)EPSS 0.4%CVE-2026-24708HIGHAn issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a rooEPSS 0.4%CVE-2022-4983MEDIUMTEC-IT TBarCode SDK 11.15 Remote File CreateEPSS 0.4%CVE-2026-48798HIGHSSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP FilenamesEPSS 0.4%CVE-2020-36772MEDIUMCloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to reEPSS 0.4%CVE-2026-9587HIGHAuthenticated Local File Inclusion (LFI) in Switchvox SMB Web PortalEPSS 0.4%CVE-2011-10030HIGHFoxit PDF Reader < 4.3.1.0218 JavaScript File WriteEPSS 0.4%CVE-2026-15736HIGHMultiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemyEPSS 0.4%CVE-2025-29930MEDIUMimFAQ allows local file inclusion in seo.phpEPSS 0.4%CVE-2025-59511HIGHWindows WLAN Service Elevation of Privilege VulnerabilityEPSS 0.4%