Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-27115HIGHADB Explorer is Vulnerable to Arbitrary Directory Deletion via Command-Line ArgumentEPSS 0.2%CVE-2026-46345HIGHcompliance-trestle - jinja has an Arbitrary File Write via Path TraversalEPSS 0.2%CVE-2026-81347MEDIUMFrontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path TraversalEPSS 0.2%CVE-2026-10559MEDIUMSourceCodester Pizzafy Ecommerce System index.php file inclusionEPSS 0.2%CVE-2026-10558MEDIUMSourceCodester Pizzafy Ecommerce System index.php file inclusionEPSS 0.2%CVE-2026-15382MEDIUMUltimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fontsEPSS 0.2%CVE-2026-79674HIGHNLTK 3.10.2 Path Traversal via corpus-reader constructorsEPSS 0.2%CVE-2026-19860MEDIUMJetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation CallbackEPSS 0.2%CVE-2025-8998LOWIt was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. ThiEPSS 0.2%CVE-2026-66310HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-4230HIGHExternal Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic SoftEPSS 0.2%CVE-2023-34982MEDIUMAVEVA Operations Control Logger External Control of File Name or Path EPSS 0.2%CVE-2024-25965MEDIUMDell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilegeEPSS 0.2%CVE-2026-25636HIGHcalibre has a Path Traversal Leading to Arbitrary File Corruption and Code ExecutionEPSS 0.2%CVE-2021-34761MEDIUMCisco Firepower Threat Defense Software CLI Arbitrary File Write VulnerabilityEPSS 0.2%CVE-2025-65799MEDIUMA lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traverEPSS 0.2%CVE-2021-1306MEDIUMCisco ADE-OS Local File Inclusion VulnerabilityEPSS 0.2%CVE-2026-54134HIGHOctoPrint: File exfiltration possible via query parameters on upload endpointsEPSS 0.2%CVE-2026-85160HIGHAVideo through c91b5975d CSRF and Path Traversal via stopLive.phpEPSS 0.2%CVE-2024-36473MEDIUMTrend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to loEPSS 0.2%