Weaknesses of type CWE-807

109 results

Decisão de segurança baseada em entrada não confiável

A aplicação toma decisões críticas de segurança (autenticação, autorização, controle de acesso) usando dados que vêm diretamente do usuário ou cliente sem validação adequada. Um atacante pode manipular esses dados para contornar controles de segurança e ganhar acesso não autorizado.

Example

Um sistema que verifica permissão de admin apenas consultando um campo 'isAdmin' vindo do formulário POST do cliente, ou que valida um JWT usando um secret armazenado no cookie do próprio usuário. Um atacante edita o valor local e a aplicação confia cegamente.

How to mitigate

Nunca confie em dados do cliente para decisões de segurança: sempre valide e recalcule permissões no servidor usando fonte confiável (banco de dados, sessão segura, token assinado com chave servidor). Implemente verificação de autorização em cada endpoint sensível, independentemente do que o cliente envie.

CVE-2026-35670MEDIUMOpenClaw < 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology ChatEPSS 0.2%CVE-2026-35617LOWOpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayNameEPSS 0.2%CVE-2024-9310MEDIUMTraffic Alert and Collision Avoidance System (TCAS) II has a Reliance on Untrusted Inputs in a Security Decision vulnerabilityEPSS 0.2%CVE-2026-35655MEDIUMOpenClaw < 2026.3.22 - Identity Spoofing via rawInput Tool in ACP Permission ResolutionEPSS 0.2%CVE-2026-29134MEDIUMGINA Domain SwitchEPSS 0.2%CVE-2026-58239LOWMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.2%CVE-2026-44649CRITICALSillyTavern: Authentication Bypass via SSO Header InjectionEPSS 0.2%CVE-2025-55735MEDIUMflaskBlog Stored XSS VulnerabilityEPSS 0.2%CVE-2026-64934MEDIUMMira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decisionEPSS 0.2%CVE-2019-25711MEDIUMSpotFTP Password Recover 2.4.2 Denial of Service via Name FieldEPSS 0.2%CVE-2026-41299HIGHOpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance GuardEPSS 0.2%CVE-2026-9561HIGHEclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP addrEPSS 0.2%CVE-2019-25544MEDIUMPidgin 2.13.0 Denial of Service via Malformed UsernameEPSS 0.2%CVE-2019-25621MEDIUMPixel Studio 2.17 Denial of Service via Malformed InputEPSS 0.2%CVE-2024-28824HIGHPrivilege escalation in mk_informix pluginEPSS 0.2%CVE-2023-0009HIGHGlobalProtect App: Local Privilege Escalation (PE) VulnerabilityEPSS 0.2%CVE-2024-28829MEDIUMPrivilege escalation in mk_informix pluginEPSS 0.2%CVE-2026-48980MEDIUMpam_usb: getenv() used in PAM context allows environment variable injection into local-check logicEPSS 0.2%CVE-2026-53860LOWOpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubblesEPSS 0.2%CVE-2026-12058MEDIUMThe connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.EPSS 0.2%