Weaknesses of type CWE-862

8,626 results

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para fazê-lo. É a brecha clássica onde o código autentifica (sabe quem é) mas não autoriza (valida se pode). Resultado: usuários comuns acessam dados sensíveis ou administrativos.

Example

Um sistema de e-commerce autentica o cliente, mas ao acessar /pedidos/123, não verifica se o pedido pertence àquele usuário — qualquer cliente logado vê qualquer pedido alheio. Ou um painel administrativo expõe endpoints que deleta contas, mas qualquer conta logada consegue chamar.

How to mitigate

Implemente verificação de autorização em todo endpoint ou ação sensível: valide não só identidade, mas permissões (roles, ACLs, policies). Use middleware ou decoradores (@RequireRole, @Authorize) e teste cenários onde usuários com privileégio baixo tentam acessar recursos alheios ou funções restritas.

CVE-2026-74928HIGHWP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello Import RoutesEPSS 0.4%CVE-2026-90551MEDIUMWWBN AVideo Missing Authorization via video_from_program APIEPSS 0.4%CVE-2026-76074MEDIUMAutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_campaign_monitor_get_lists AJAX ActionEPSS 0.4%CVE-2022-48350HIGHThe HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentEPSS 0.4%CVE-2024-0596MEDIUMAwesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via editor_html()EPSS 0.4%CVE-2023-5506MEDIUMImageMapper <= 1.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Page/Post Deletion via imgmap_delete_area_ajaxEPSS 0.4%CVE-2025-1404MEDIUMSecure Copy Content Protection and Content Locking <= 4.4.7 - Missing Authorization to Unauthenticated User Email Retrieval via ays_sccp_reports_user_search FunctionEPSS 0.4%CVE-2023-5387MEDIUMFunnelforms Free <= 3.4 - Missing Authorization to Enable/Disable Dark ModeEPSS 0.4%CVE-2023-5415MEDIUMFunnelforms Free <= 3.4 - Missing Authorization to New Category CreationEPSS 0.4%CVE-2023-5416MEDIUMFunnelforms Free <= 3.4 - Missing Authorization to Category DeletionEPSS 0.4%CVE-2026-3117MEDIUMInstance and webhook GitLab plugin commands were able to be run by non-admin usersEPSS 0.4%CVE-2026-88802HIGHMDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post DeletionEPSS 0.4%CVE-2024-8431MEDIUMPhoto Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title DisclosureEPSS 0.4%CVE-2024-43296MEDIUMWordPress HTML5 Video Player plugin <= 2.5.30 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-44208HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15. An app may be able to bypass certain PrEPSS 0.4%CVE-2025-49041MEDIUMWordPress Get Cash plugin <= 3.2.3 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-25768HIGHLavinMQ is missing vhost access controlEPSS 0.4%CVE-2025-68019MEDIUMWordPress SEO Booster plugin <= 6.1.8 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2023-48759HIGHWordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerabilityEPSS 0.4%CVE-2023-47760MEDIUMWordPress Essential Blocks plugin <= 4.2.0 - Broken Access Control vulnerabilityEPSS 0.4%