Weaknesses of type CWE-862

8,689 results

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para fazê-lo. É a brecha clássica onde o código autentifica (sabe quem é) mas não autoriza (valida se pode). Resultado: usuários comuns acessam dados sensíveis ou administrativos.

Example

Um sistema de e-commerce autentica o cliente, mas ao acessar /pedidos/123, não verifica se o pedido pertence àquele usuário — qualquer cliente logado vê qualquer pedido alheio. Ou um painel administrativo expõe endpoints que deleta contas, mas qualquer conta logada consegue chamar.

How to mitigate

Implemente verificação de autorização em todo endpoint ou ação sensível: valide não só identidade, mas permissões (roles, ACLs, policies). Use middleware ou decoradores (@RequireRole, @Authorize) e teste cenários onde usuários com privileégio baixo tentam acessar recursos alheios ou funções restritas.

CVE-2024-34768MEDIUMWordPress Fastly plugin <= 1.2.25 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-41128MEDIUMCraft CMS has a Missing Authorization Check on User Group Removal via save-permissions ActionEPSS 0.4%CVE-2023-4106MEDIUMA guest user can perform various actions on public playbooksEPSS 0.4%CVE-2026-44012HIGHCraft CMS: Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information DisclosureEPSS 0.4%CVE-2024-25922MEDIUMWordPress Peach Payments Gateway plugin <= 3.1.9 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-50283MEDIUMCraft CMS: Unauthorized Deletion of Source Assets During File ReplacementEPSS 0.4%CVE-2024-9364MEDIUMSendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log DeletionEPSS 0.4%CVE-2025-31794MEDIUMWordPress WR Price List Manager For Woocommerce plugin <= 1.0.8 - Arbitrary Content Deletion vulnerabilityEPSS 0.4%CVE-2026-47416CRITICALpraisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}EPSS 0.4%CVE-2024-32731MEDIUMMissing Authorization check in SAP My Travel RequestsEPSS 0.4%CVE-2026-47740HIGHShopper: Authorization bypass in multiple Livewire admin componentsEPSS 0.4%CVE-2026-1916HIGHWPGSI: Spreadsheet Integration <= 3.8.3 - Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 TokenEPSS 0.4%CVE-2026-58377HIGHJeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret KeysEPSS 0.4%CVE-2024-11709MEDIUMAI Post Generator | AutoWriter <= 3.5 - Missing Authorization to Authenticated (Contributor+) Post/Page DeletionEPSS 0.4%CVE-2026-90546MEDIUMWWBN AVideo Missing Authorization via like.json.phpEPSS 0.4%CVE-2024-10437MEDIUMWPC Smart Messages for WooCommerce <= 4.2.1 - Missing Authorization to Authenticated (Subscriber+) Message Activation/DeactivationEPSS 0.4%CVE-2025-6721MEDIUMVchasno Kasa <= 1.0.3 - Missing Authorization to Unauthenticated Invoice GenerationEPSS 0.4%CVE-2026-7368HIGHYarbo Android/iOS Mobile Application and Cloud Infrastructure Missing AuthorizationEPSS 0.4%CVE-2026-24987MEDIUMWordPress WP System Log plugin <= 1.2.7 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-46450HIGHIncorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentEPSS 0.4%