Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2024-38049MEDIUMWindows Distributed Transaction Coordinator Remote Code Execution VulnerabilityEPSS 1.6%CVE-2020-15264HIGHPrivilege Escalation in BoxstarterEPSS 1.6%CVE-2024-11042CRITICALArbitrary File Delete in invoke-ai/invokeaiEPSS 1.5%CVE-2026-26975HIGHMusic Assistant Server Path Traversal in Playlist Update API Allows Remote Code ExecutionEPSS 1.5%CVE-2025-46762HIGHApache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadataEPSS 1.5%CVE-2020-26078MEDIUMCisco IoT Field Network Director File Overwrite VulnerabilityEPSS 1.5%CVE-2022-0593—Login with phone number < 1.3.7 - Unauthenticated remote plugin deletionEPSS 1.4%CVE-2020-5296MEDIUMArbitrary File Deletion vulnerability in OctoberCMSEPSS 1.4%CVE-2022-20789MEDIUMCisco Unified Communications Products Arbitrary File Write VulnerabilityEPSS 1.4%CVE-2019-3681HIGHosc: stores downloaded (supposed) RPM in network-controlled filesystem pathsEPSS 1.4%CVE-2025-4603CRITICALeMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File DeletionEPSS 1.4%CVE-2024-43581HIGHMicrosoft OpenSSH for Windows Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-27944HIGHA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmEPSS 1.4%CVE-2024-38029HIGHMicrosoft OpenSSH for Windows Remote Code Execution VulnerabilityEPSS 1.4%CVE-2026-8450CRITICALHTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()EPSS 1.4%CVE-2026-11526CRITICALGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandleEPSS 1.4%CVE-2024-27945HIGHA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a priEPSS 1.4%CVE-2025-49760LOWWindows Storage Spoofing VulnerabilityEPSS 1.3%CVE-2025-55746CRITICALDirectus allows unauthenticated file upload and file modification due to lacking input sanitizationEPSS 1.3%CVE-2024-38165MEDIUMWindows Compressed Folder Tampering VulnerabilityEPSS 1.3%