Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-52875HIGHStreambert: Arbitrary Directory Creation and File Manipulation via Backup HandlerEPSS 0.2%CVE-2025-32802MEDIUMInsecure handling of file paths allows multiple local attacksEPSS 0.2%CVE-2026-58484HIGHNetwork-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruningEPSS 0.2%CVE-2026-30284HIGHAn arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the EPSS 0.2%CVE-2026-53449MEDIUMCoturn: Arbitrary File Write via CLI psd CommandEPSS 0.2%CVE-2026-30289HIGHAn arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal EPSS 0.2%CVE-2024-20366HIGHA vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator EPSS 0.2%CVE-2026-82194MEDIUMWPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path TraversalEPSS 0.2%CVE-2026-47425MEDIUMRattler vulnerable to entry-point path traversal in noarch:python install (arbitrary file write)EPSS 0.2%CVE-2026-92595MEDIUMNodemailer before 9.1.1 Security Sandbox Bypass via resolveContentEPSS 0.2%CVE-2026-17014MEDIUMWP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzipsEPSS 0.2%CVE-2026-52872HIGHStreambert: Local File Exfiltration and Overwrite via Subtitle file: ProtocolEPSS 0.2%CVE-2026-2604MEDIUMEvolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handlingEPSS 0.2%CVE-2025-36398MEDIUMDS8900F and DS8A00 Information DisclosureEPSS 0.2%CVE-2025-27137MEDIUMDependency-Track vulnerable to local file inclusion via custom notification templatesEPSS 0.2%CVE-2026-13748MEDIUMSnowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path RestrictionEPSS 0.2%CVE-2026-42424MEDIUMOpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA PathsEPSS 0.2%CVE-2026-20175MEDIUMCisco Finesse File Inclusion VulnerabilityEPSS 0.2%CVE-2026-77006CRITICALWebTotem Backups < 1.1.0 - Subscriber+ Arbitrary File Deletion via Path TraversalEPSS 0.2%CVE-2023-20234MEDIUMA vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on theEPSS 0.2%