Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-72742CRITICALDSPy 3.3.0b1 Local File Read via Image/Audio Output Field ParsingEPSS 0.4%CVE-2026-78208HIGHexceljs through 4.4.0 Path Traversal via Unvalidated addImage filenameEPSS 0.4%CVE-2025-59483HIGHBIG-IP Configuration utility and tmsh vulnerabilityEPSS 0.4%CVE-2026-47214HIGHDocling: Unsafe URI and Path Handling in HTML BackendEPSS 0.4%CVE-2026-45556CRITICALRoxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`EPSS 0.4%CVE-2026-79653MEDIUMIn Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enaEPSS 0.4%CVE-2026-35076HIGHArbitrary file delete vulnerability in method bac-scanresultEPSS 0.4%CVE-2026-35078HIGHArbitrary file delete vulnerability in method ugw-logstopEPSS 0.4%CVE-2026-35079HIGHArbitrary file delete vulnerability in method ugw-restoreEPSS 0.4%CVE-2024-12036HIGHCS Framework <= 7.1 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.4%CVE-2026-35080HIGHArbitrary file delete vulnerability in method ugw-restoreinfoEPSS 0.4%CVE-2026-35077HIGHArbitrary file delete vulnerability in method ugw-delete-fileEPSS 0.4%CVE-2024-6937MEDIUMformtools.org Form Tools Import Option List edit.php curl_exec file inclusionEPSS 0.4%CVE-2026-60009HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled EPSS 0.4%CVE-2026-62385HIGHNLTK 3.9.4 Path Traversal via FrameNet and NKJP ReadersEPSS 0.4%CVE-2023-21566HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-76210HIGHphpMyFAQ before v4.1.6 Local File Disclosure via PDF ExportEPSS 0.4%CVE-2026-84478MEDIUMWWBN AVideo Unauthenticated Arbitrary Log File DeletionEPSS 0.4%CVE-2026-30282CRITICALAn arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internalEPSS 0.4%CVE-2026-28459HIGHOpenClaw < 2026.2.12 - Arbitrary File Write via Untrusted sessionFile PathEPSS 0.4%