Weaknesses of type CWE-862

8,624 results

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para fazê-lo. É a brecha clássica onde o código autentifica (sabe quem é) mas não autoriza (valida se pode). Resultado: usuários comuns acessam dados sensíveis ou administrativos.

Example

Um sistema de e-commerce autentica o cliente, mas ao acessar /pedidos/123, não verifica se o pedido pertence àquele usuário — qualquer cliente logado vê qualquer pedido alheio. Ou um painel administrativo expõe endpoints que deleta contas, mas qualquer conta logada consegue chamar.

How to mitigate

Implemente verificação de autorização em todo endpoint ou ação sensível: valide não só identidade, mas permissões (roles, ACLs, policies). Use middleware ou decoradores (@RequireRole, @Authorize) e teste cenários onde usuários com privileégio baixo tentam acessar recursos alheios ou funções restritas.

CVE-2025-23025CRITICALPrivilege escalation (PR) through realtime WYSIWYG editing in XWikiEPSS 0.4%CVE-2024-1798MEDIUMTutor LMS – Migration Tool <= 2.2.0 - Missing Authorization in tutor_lp_export_xmlEPSS 0.4%CVE-2024-9829MEDIUMDownload Plugin <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment DownloadEPSS 0.4%CVE-2025-26372HIGHA CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authEPSS 0.4%CVE-2025-12714MEDIUMRank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings ModificationEPSS 0.4%CVE-2024-9583MEDIUMRSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing AuthorizationEPSS 0.4%CVE-2025-2224MEDIUMDirectorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post PublishingEPSS 0.4%CVE-2025-54159HIGHMissing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrEPSS 0.4%CVE-2024-10078MEDIUMWP Easy Post Types <= 1.4.4 - Authenticated (Subscriber+) Missing Authorization via Multiple FunctionsEPSS 0.4%CVE-2024-49325MEDIUMWordPress Photo Gallery Builder plugin <= 3.0 - Broken Access Control to Notice Dismissal vulnerabilityEPSS 0.4%CVE-2026-67529MEDIUMOpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)EPSS 0.4%CVE-2024-55998MEDIUMWordPress Popup Surveys & Polls for WordPress (Mare.io) plugin <= 1.36 - Settings Change vulnerabilityEPSS 0.4%CVE-2024-6824MEDIUMPremium Addons for Elementor <= 4.10.38 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion and Arbitrary Title UpdateEPSS 0.4%CVE-2026-57221MEDIUMRabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged usersEPSS 0.4%CVE-2026-3208MEDIUMMercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticated PIX Payment QR Code Image DisclosureEPSS 0.4%CVE-2023-32129MEDIUMWordPress Editorialmag theme <= 1.1.9 - Authenticated Arbitrary Plugin ActivationEPSS 0.4%CVE-2023-4025MEDIUMRadio Player <= 2.0.73 - Missing Authorization to Player UpdateEPSS 0.4%CVE-2024-1123MEDIUMEventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post OverwriteEPSS 0.4%CVE-2024-1662HIGHInformation Disclosure in Porty's PowerBankEPSS 0.4%CVE-2024-56004MEDIUMWordPress Easy Site Importer plugin <= 1.0.1 - Settings Change vulnerabilityEPSS 0.4%