Weaknesses of type CWE-862

8,689 results

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para fazê-lo. É a brecha clássica onde o código autentifica (sabe quem é) mas não autoriza (valida se pode). Resultado: usuários comuns acessam dados sensíveis ou administrativos.

Example

Um sistema de e-commerce autentica o cliente, mas ao acessar /pedidos/123, não verifica se o pedido pertence àquele usuário — qualquer cliente logado vê qualquer pedido alheio. Ou um painel administrativo expõe endpoints que deleta contas, mas qualquer conta logada consegue chamar.

How to mitigate

Implemente verificação de autorização em todo endpoint ou ação sensível: valide não só identidade, mas permissões (roles, ACLs, policies). Use middleware ou decoradores (@RequireRole, @Authorize) e teste cenários onde usuários com privileégio baixo tentam acessar recursos alheios ou funções restritas.

CVE-2022-41695MEDIUMWordPress Traffic Manager Plugin <= 1.4.5 is vulnerable to Broken Access ControlEPSS 0.4%CVE-2024-3626MEDIUMEmail Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing AuthorizationEPSS 0.4%CVE-2026-63741MEDIUMSurrealDB before 3.1.0 Authentication Bypass via USE statementEPSS 0.4%CVE-2024-5669MEDIUMXPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2025-63063MEDIUMWordPress Yandex.Metrica plugin <= 1.2.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-69148HIGHMLflow: CreateModelVersion source validation does not check READ permission on referenced run_idEPSS 0.4%CVE-2025-12934HIGHBeaver Builder – WordPress Page Builder <= 2.9.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post UpdateEPSS 0.4%CVE-2026-73287MEDIUMRustFS: FTPS MKD bypasses IAM CreateBucket authorizationEPSS 0.4%CVE-2026-28159MEDIUMWordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-4881MEDIUMIn affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make serverEPSS 0.4%CVE-2026-39433MEDIUMWordPress WPAMS plugin < 49.5.3 - Arbitrary Content Deletion vulnerabilityEPSS 0.4%CVE-2024-9223MEDIUMWPDash Notes <= 1.3.5 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information ExposureEPSS 0.4%CVE-2026-25454MEDIUMWordPress The League theme <= 4.4.1 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-54746MEDIUMHatchet: Cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and UnsubscribeEPSS 0.4%CVE-2026-47120HIGHNezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)EPSS 0.4%CVE-2024-21630MEDIUMZulip non-admins can invite new users to streams they would not otherwise be able to add existing users toEPSS 0.4%CVE-2024-8552MEDIUMDownload Monitor <= 5.0.9 - Missing Authorization to Authenticated (Subscriber+) Shop EnableEPSS 0.4%CVE-2025-30591MEDIUMWordPress Music Press Pro plugin <= 1.4.6 Broken Access Control VulnerabilityEPSS 0.4%CVE-2026-88270MEDIUMGV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of ServiceEPSS 0.4%CVE-2024-34799MEDIUMWordPress BookingPress plugin <= 1.0.82 - Appointment Duration Manipulation vulnerabilityEPSS 0.4%