Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-30282CRITICALAn arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internalEPSS 0.4%CVE-2026-76217HIGHGitPython before 3.1.58 Arbitrary File Read via pathspec-from-fileEPSS 0.4%CVE-2025-55316HIGHAzure Connected Machine Agent Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-19913HIGHCVE-2026-19913EPSS 0.4%CVE-2026-43891HIGHchangedetection.io: Arbitrary Local File Read via crafted backup restoreEPSS 0.4%CVE-2024-12861MEDIUMW2S – Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.4%CVE-2026-23835MEDIUMLobeHub Vulnerable to Improper Authorization in Presigned UploadEPSS 0.4%CVE-2026-31939HIGHPath Traversal (Arbitrary File Delete) in Chamilo LMSEPSS 0.4%CVE-2026-22783CRITICALIris Allows Arbitrary File Deletion via Mass Assignment in Datastore File ManagementEPSS 0.4%CVE-2025-58769LOWauth0-PHP: Improper File Type Handling in Bulk User ImportEPSS 0.4%CVE-2026-83603HIGHNetdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCEEPSS 0.3%CVE-2026-40893HIGHGotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and MoveEPSS 0.3%CVE-2020-37078HIGHi-doit Open Source CMDB 1.14.1 - Arbitrary File DeletionEPSS 0.3%CVE-2026-91797HIGHFoxit PDF Editor/Reader Portfolio Directory Traversal Remote Code Execution VulnerabilityEPSS 0.3%CVE-2020-36878HIGHReQuest Serious Play F3 Media Player <= 3.0.0 Directory Traversal File DisclosureEPSS 0.3%CVE-2020-37080HIGHwebTareas 2.0.p8 - Arbitrary File DeletionEPSS 0.3%CVE-2025-0124MEDIUMPAN-OS: Authenticated File Deletion Vulnerability on the Management Web InterfaceEPSS 0.3%CVE-2024-1244CRITICALRemote code execution and local privilege escalation due to UNC access and NetNTLMv2 hash theftEPSS 0.3%CVE-2026-85176HIGHDbGate through 7.2.6 Arbitrary File Read and Write via file:// jslidEPSS 0.3%CVE-2026-77693HIGHOrder Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajaxEPSS 0.3%