Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-20175MEDIUMCisco Finesse File Inclusion VulnerabilityEPSS 0.2%CVE-2026-30287HIGHAn arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to overwrite critical iEPSS 0.2%CVE-2026-5054HIGHNoMachine External Control of File Path Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-12480MEDIUMArbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/kerasEPSS 0.2%CVE-2025-3033HIGHOpening local .url files could lead to another file being openedEPSS 0.2%CVE-2026-27008MEDIUMOpenClaw hardened the skill download target directory validationEPSS 0.2%CVE-2026-63225MEDIUMRedocly CLI: Path traversal when using `split` commandEPSS 0.2%CVE-2024-33671HIGHAn issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can bEPSS 0.2%CVE-2026-26158HIGHBusybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entriesEPSS 0.2%CVE-2026-50158HIGHyutu: Arbitrary File Write via MCP `caption-download` ToolEPSS 0.2%CVE-2024-23317MEDIUMExternal Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the ControEPSS 0.2%CVE-2026-0965LOWLibssh: libssh: denial of service via improper configuration file handlingEPSS 0.2%CVE-2023-28603HIGHZoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete localEPSS 0.2%CVE-2026-49836MEDIUMpsd-tools: arbitrary file write via smart-object filenameEPSS 0.2%CVE-2026-8921HIGHExternal Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM priviEPSS 0.2%CVE-2026-42881HIGHSTIGQter: Arbitrary File Write leading to Local Code Execution via Export HTMLEPSS 0.2%CVE-2025-64738MEDIUMZoom Workplace for macOS - External Control of File Name or PathEPSS 0.2%CVE-2026-5053HIGHNoMachine External Control of File Path Arbitrary File Deletion VulnerabilityEPSS 0.1%CVE-2026-73770HIGHAuthenticated Arbitrary File Write Vulnerability Leading to Remote Code Execution in AOS-CXEPSS 0.1%CVE-2026-49358LOWPhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFilesEPSS 0.1%