Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-53508MEDIUMoasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)EPSS 0.3%CVE-2026-32204HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-14059MEDIUMEmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path TraversalEPSS 0.3%CVE-2025-0898MEDIUMXpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVGEPSS 0.3%CVE-2026-86995MEDIUMn8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository ReadEPSS 0.3%CVE-2022-34669HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modiEPSS 0.3%CVE-2025-54780HIGHglpi-screenshot-plugin exposes local files in /ajax/screenshot.phpEPSS 0.3%CVE-2026-42597MEDIUMGotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// schemeEPSS 0.3%CVE-2023-45588HIGHAn external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installEPSS 0.3%CVE-2026-53580HIGHTrilium arbitrary file read and denial of service via file:// URLs in the automatic image-download featureEPSS 0.3%CVE-2026-26228LOWVLC for Android < 3.7.0 Remote Access Path TraversalEPSS 0.3%CVE-2026-16054CRITICALDrag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce OracleEPSS 0.3%CVE-2026-12513MEDIUMShared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path TraversalEPSS 0.3%CVE-2025-4674HIGHUnexpected command execution in untrusted VCS repositories in cmd/goEPSS 0.3%CVE-2025-61879HIGHIn Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.EPSS 0.3%CVE-2026-45725HIGHcompliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path TraversalEPSS 0.3%CVE-2026-54584MEDIUMmport trusts environment-controlled temporary directories in privileged metadata extractionEPSS 0.3%CVE-2026-3602MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injectionEPSS 0.3%CVE-2026-34492HIGHAirwall - Arbitrary file readEPSS 0.3%CVE-2026-30240CRITICALBudibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment SecretsEPSS 0.3%