Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-55527HIGHPraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable locationEPSS 0.3%CVE-2025-11973MEDIUM简数采集器 <= 2.6.3 - Authenticated (Admin+) Arbitrary File ReadEPSS 0.3%CVE-2026-41088HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-39303MEDIUMWeblate vulnerabler to improper sanitization of project backupsEPSS 0.3%CVE-2026-6205HIGHAn external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-7280EPSS 0.3%CVE-2026-44641HIGHMicrosoft APM: plugin.json component paths escape plugin root and copy arbitrary host files during installEPSS 0.3%CVE-2026-41412MEDIUMalf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension ScriptEPSS 0.3%CVE-2025-64739MEDIUMZoom Clients - External Control of File Name or PathEPSS 0.3%CVE-2026-19084HIGHShared Files < 1.7.70 - Unauthenticated Arbitrary File ReadEPSS 0.3%CVE-2020-36868HIGHNagios XI < 5.7.3 Privilege escalation via Insecure getprofile.sh ScriptEPSS 0.3%CVE-2026-16926CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2025-62382HIGHFrigate Vulnerable to Arbitrary File Read via Export Thumbnail "image_path" parameterEPSS 0.3%CVE-2026-35032HIGHJellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tunerEPSS 0.3%CVE-2026-42593MEDIUMGotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routesEPSS 0.3%CVE-2020-1984HIGHSecdo: Privilege escalation via hardcoded script pathEPSS 0.3%CVE-2025-10306LOWBackup Bolt <= 1.4.1 - Authenticated (Admin+) Arbitrary File DownloadEPSS 0.3%CVE-2021-22539HIGHCode execution in VSCode-bazel via malicious Bazel config filesEPSS 0.3%CVE-2025-0202MEDIUMTCS BaNCS REPORTS_SHOW_FILE.jsp file inclusionEPSS 0.3%CVE-2026-1669HIGHArbitrary File Read in Keras via HDF5 External DatasetsEPSS 0.3%CVE-2026-62865HIGHTypeBot: Arbitrary server file read via Send Email block attachment pathEPSS 0.3%