Weaknesses of type CWE-73
668 resultsControle de acesso impróprio
Ocorre quando a aplicação falha em validar adequadamente quem pode acessar um recurso, função ou dado sensível. O código não verifica permissões corretamente — ou não verifica de jeito nenhum — permitindo que usuários não autorizados realizem ações que deveriam estar restritas.
Example
Um endpoint de API que deleta um cliente valida apenas se o usuário está logado, mas não verifica se ele é admin ou proprietário do cliente. Qualquer usuário autenticado consegue deletar qualquer cliente da plataforma.
How to mitigate
Implemente verificação explícita de permissões antes de toda ação sensível: verifique papel (role), escopo e propriedade do recurso. Use padrões como RBAC ou ABAC e teste casos onde usuários tentam acessar dados alheios.
CVE-2026-47643CRITICALAzure Stack Edge Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-7626HIGHWP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) <= 1.6.9 - Improper Path Validation to Authenticated (Subscriber+) Arbitrary File Move and ReadEPSS 0.8%CVE-2024-7911MEDIUMSourceCodester Simple Online Bidding System index.php file inclusionEPSS 0.7%CVE-2021-47746HIGHNodeBB Plugin Emoji 3.2.1 - Arbitrary File WriteEPSS 0.7%CVE-2019-14905HIGHA vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in AnsibEPSS 0.7%CVE-2024-0728MEDIUMForU CMS channel.php file inclusionEPSS 0.7%CVE-2024-30265HIGHVoilà Local file inclusionEPSS 0.7%CVE-2023-6569CRITICALExternal Control of File Name or Path in h2oai/h2o-3EPSS 0.7%CVE-2024-10492LOWKeycloak-quarkus-server: keycloak path trasversalEPSS 0.7%CVE-2023-1105HIGHExternal Control of File Name or Path in flatpressblog/flatpressEPSS 0.7%CVE-2026-26157HIGHBusybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitizationEPSS 0.7%CVE-2026-13014CRITICALRemote Code Execution vulnerability in "Suspicious" applicationEPSS 0.7%CVE-2026-73720HIGHAuthenticated Insecure File Handling allows Remote Code Execution in HPE Networking Fabric Composer APIEPSS 0.7%CVE-2025-3419HIGHEvent Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File ReadEPSS 0.7%CVE-2024-23634MEDIUMGeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store APIEPSS 0.7%CVE-2026-40342CRITICALFirebird: Path Traversal + Arbitrary File Write Leads to Remote Code ExecutionEPSS 0.7%CVE-2026-30281CRITICALAn arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import EPSS 0.7%CVE-2024-7744MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP ServerEPSS 0.7%CVE-2024-0100MEDIUMCVEEPSS 0.7%CVE-2026-57898CRITICALIn Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to EPSS 0.7%