Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-75830HIGHgrav-plugin-api before 1.0.15 Path Traversal via batchCopyEPSS 0.3%CVE-2026-15921LOWnvm path traversal via a malicious mirror's LTS codename writes outside the alias directoryEPSS 0.3%CVE-2026-0259MEDIUMWildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)EPSS 0.3%CVE-2026-12979MEDIUMFunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template ImporterEPSS 0.3%CVE-2024-51553HIGHPredictable FilenameEPSS 0.3%CVE-2026-23521MEDIUMTraccar vulnerable to Path Traversal and External Control of File Name or PathEPSS 0.3%CVE-2025-49588HIGHLinkwarden Local File Inclusion VulnerabilityEPSS 0.3%CVE-2026-75913HIGHCodeWhale before 0.8.64 Argument Injection via git_showEPSS 0.3%CVE-2026-7633MEDIUMTotolink N300RH cstecgi.cgi setUploadSetting file inclusionEPSS 0.3%CVE-2026-41177MEDIUMSquidex has Blind SSRF via file:// Protocol in Restore API leading to Local File InteractionEPSS 0.3%CVE-2026-30903CRITICALExternal Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to coEPSS 0.3%CVE-2026-73496HIGHMCP Atlassian: Arbitrary server-side file read via attachment uploadEPSS 0.3%CVE-2024-12267MEDIUMDrag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File DeletionEPSS 0.3%CVE-2026-34030MEDIUMImproper branch-code validation in Wertheim SafeController Software allows file path manipulationEPSS 0.3%CVE-2026-53581CRITICALntp: write path traversalEPSS 0.3%CVE-2026-24287HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62804HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-31492HIGHAn external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installEPSS 0.3%CVE-2026-61647HIGH@roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended vault directoryEPSS 0.3%CVE-2025-29866HIGH: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free EPSS 0.3%