Weaknesses of type CWE-807

109 results

Decisão de segurança baseada em entrada não confiável

A aplicação toma decisões críticas de segurança (autenticação, autorização, controle de acesso) usando dados que vêm diretamente do usuário ou cliente sem validação adequada. Um atacante pode manipular esses dados para contornar controles de segurança e ganhar acesso não autorizado.

Example

Um sistema que verifica permissão de admin apenas consultando um campo 'isAdmin' vindo do formulário POST do cliente, ou que valida um JWT usando um secret armazenado no cookie do próprio usuário. Um atacante edita o valor local e a aplicação confia cegamente.

How to mitigate

Nunca confie em dados do cliente para decisões de segurança: sempre valide e recalcule permissões no servidor usando fonte confiável (banco de dados, sessão segura, token assinado com chave servidor). Implemente verificação de autorização em cada endpoint sensível, independentemente do que o cliente envie.

CVE-2026-27707HIGHPlex-configured Seerr instances vulnerable to unauthenticated account registration via Jellyfin authentication endpointEPSS 0.5%CVE-2024-7005HIGHInsufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced EPSS 0.5%CVE-2026-31892HIGHWorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference ModeEPSS 0.5%CVE-2025-59152HIGHX-Forwarded-For Header Spoofing Bypasses Litestar Rate LimitingEPSS 0.5%CVE-2026-64827CRITICALTelenia TVox 26.5.3 Authentication Bypass via set_env.phpEPSS 0.5%CVE-2024-52327MEDIUMECOVACS lawnmower and vacuum cloud service live video PIN bypassEPSS 0.5%CVE-2025-66507HIGH1Panel – CAPTCHA Bypass via Client-Controlled FlagEPSS 0.5%CVE-2024-21510MEDIUMVersions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XEPSS 0.5%CVE-2026-59157MEDIUMwebhookd: Unrestricted HTTP Header to Shell Variable InjectionEPSS 0.5%CVE-2026-39807MEDIUMClient-supplied URI scheme trusted without transport verification in banditEPSS 0.5%CVE-2025-13926CRITICALContemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security DecisionEPSS 0.4%CVE-2025-24369LOWAnubis has a bot protection bypass when a sophisticated attacker asks to pass a challenge of difficulty 0EPSS 0.4%CVE-2026-16093MEDIUMKeycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headersEPSS 0.4%CVE-2026-13059HIGHImproper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control BypassEPSS 0.4%CVE-2026-54730HIGHauthentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageViewEPSS 0.4%CVE-2020-5252MEDIUMMalicious package may avoid detection in python auditingEPSS 0.4%CVE-2026-23848MEDIUMMyTube has Rate Limiting Bypass via X-Forwarded-For Header SpoofingEPSS 0.4%CVE-2026-25958HIGHCube privilege escalation via a specially crafted requestEPSS 0.4%CVE-2026-86863CRITICALpgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication modeEPSS 0.4%CVE-2024-45654MEDIUMIBM Security ReaQta improper input validationEPSS 0.4%