Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-39378MEDIUMnbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image EmbeddingEPSS 0.3%CVE-2026-28442HIGHZimaOS: Arbitrary Deletion of Internal System Files via API Path ManipulationEPSS 0.3%CVE-2026-40605MEDIUMTautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APIEPSS 0.3%CVE-2026-10694MEDIUMSourceCodester Online Food Ordering System index.php include file inclusionEPSS 0.3%CVE-2019-25472HIGHIntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFileEPSS 0.3%CVE-2026-77005CRITICALCode Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path TraversalEPSS 0.3%CVE-2026-94401HIGHMISP Arbitrary Local File Read and SSRF via MISP Export UploadEPSS 0.3%CVE-2026-79426HIGHAn arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to dEPSS 0.3%CVE-2025-48067MEDIUMOctoPrint vulnerable to possible file extraction via upload endpointsEPSS 0.3%CVE-2026-5210MEDIUMSourceCodester Leave Application System file inclusionEPSS 0.3%CVE-2026-41693HIGHi18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwriteEPSS 0.3%CVE-2026-77139MEDIUMPath Traversal in extension "Mask" (mask)EPSS 0.3%CVE-2026-85687HIGHsurya 0.22.1 Unauthenticated Arbitrary File Read via screenshot serverEPSS 0.3%CVE-2026-29611HIGHOpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media HandlingEPSS 0.3%CVE-2026-46399CRITICALAuthenticated Remote Code Execution via File OverwriteEPSS 0.3%CVE-2026-73619HIGHGitPython before 3.1.57 Arbitrary File Read via Repo.archive()EPSS 0.3%CVE-2026-46397MEDIUMhaxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0EPSS 0.3%CVE-2025-8050MEDIUMExternal Control of File vulnerability has been discovered in opentext Flipper.EPSS 0.3%CVE-2025-8048MEDIUMExternal Control of File path vulnerability has been discovered on Openext Flipper.EPSS 0.3%CVE-2026-48920HIGHJenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inlinEPSS 0.3%