Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-2351MEDIUMTask Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.3%CVE-2026-45088HIGHDalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server ModeEPSS 0.3%CVE-2021-3626HIGHWindows version of Multipass unauthenticated localhost tcp control socket can perform mountsEPSS 0.2%CVE-2026-69383HIGHWindows Shell Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-78620MEDIUMImproper Path Validation in Okta Access Gateway Kerberos Configuration HandlingEPSS 0.2%CVE-2026-86741HIGHSnipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULAEPSS 0.2%CVE-2026-18048HIGHWP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path TraversalEPSS 0.2%CVE-2026-45089HIGHDalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server ModeEPSS 0.2%CVE-2026-54200HIGHTeamDavid: Local File Inclusion via the form field 'scjob'EPSS 0.2%CVE-2026-19353LOWDedeCMS Installation Wizard index.php _4_Setup file inclusionEPSS 0.2%CVE-2026-53956MEDIUMRattler vulnerable to package cache path traversal via conda package build stringEPSS 0.2%CVE-2026-77016CRITICALWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass AssignmentEPSS 0.2%CVE-2026-78679HIGHGitPython before 3.1.59 Arbitrary File Read via TagReference.createEPSS 0.2%CVE-2023-26282MEDIUMIBM Watson CP4D Data Stores file modificiationEPSS 0.2%CVE-2026-82637MEDIUMbrowser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory CreationEPSS 0.2%CVE-2026-76796MEDIUMNewell Brands DYMO Connect Desktop improper file path validationEPSS 0.2%CVE-2025-1056MEDIUMGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A nEPSS 0.2%CVE-2026-34967MEDIUMAdminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File WriteEPSS 0.2%CVE-2026-26361MEDIUMDell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker wEPSS 0.2%CVE-2026-12070HIGHTeamDavid: Arbitrary File Deletion via form field 'scjob'EPSS 0.2%