Weaknesses of type CWE-73

668 results

Controle de acesso impróprio

Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.

Example

Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.

How to mitigate

Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.

CVE-2026-43989HIGHJunoClaw: upload_wasm accepted arbitrary filesystem paths without validationEPSS 0.1%CVE-2026-42866MEDIUMTookie: Arbitrary file write via path traversal in -u username / -U userfile output filenameEPSS 0.1%CVE-2025-67461MEDIUMZoom Rooms for macOS - External Control of File Name or PathEPSS 0.1%CVE-2026-30292HIGHAn arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal fiEPSS 0.1%CVE-2025-20614MEDIUMExternal control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications mayEPSS 0.1%CVE-2026-30291HIGHAn arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internaEPSS 0.1%CVE-2026-14551HIGHLocal Privilege Escalation in servereye client (sensorhub)EPSS 0.1%CVE-2026-55062HIGHuniget: Path Traversal in Hook Files - Directory Escape VulnerabilityEPSS 0.1%CVE-2019-25618MEDIUMAdminExpress 1.2.5 Denial of Service via System CompareEPSS 0.1%CVE-2026-56390MEDIUMArbitrary Output Location Change in GNU BisonEPSS 0.1%CVE-2026-80119HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTLEPSS 0.1%CVE-2026-25605MEDIUMA vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without propEPSS 0.1%CVE-2026-78675HIGHGitPython before 3.1.59 Local File Content Disclosure via .gitmodulesEPSS 0.1%CVE-2025-66003HIGHLocal users can perform a local root exploit via smb4k mounthelperEPSS 0.1%CVE-2026-30905HIGHExternal Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenEPSS 0.1%CVE-2026-55609HIGHsublinear-time-solver: Arbitrary file write in consciousness-explorer / sublinear-time-solver MCP export_stateEPSS 0.1%CVE-2026-80118HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTLEPSS 0.1%CVE-2026-16987HIGHIBM i is Affected By An Improper Validation Vulnerability in PASE []EPSS 0.1%CVE-2026-8920HIGHImproper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service alloEPSS 0.1%CVE-2026-16898HIGHIBM i is Affected By Multiple Vulnerabilities in Network Authentication ServiceEPSS 0.1%