Weaknesses of type CWE-862

8,721 results

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para fazê-lo. É a brecha clássica onde o código autentifica (sabe quem é) mas não autoriza (valida se pode). Resultado: usuários comuns acessam dados sensíveis ou administrativos.

Example

Um sistema de e-commerce autentica o cliente, mas ao acessar /pedidos/123, não verifica se o pedido pertence àquele usuário — qualquer cliente logado vê qualquer pedido alheio. Ou um painel administrativo expõe endpoints que deleta contas, mas qualquer conta logada consegue chamar.

How to mitigate

Implemente verificação de autorização em todo endpoint ou ação sensível: valide não só identidade, mas permissões (roles, ACLs, policies). Use middleware ou decoradores (@RequireRole, @Authorize) e teste cenários onde usuários com privileégio baixo tentam acessar recursos alheios ou funções restritas.

CVE-2026-87031LOWMissing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creationEPSS 0.3%CVE-2024-7381MEDIUMGeo Controller <= 8.6.9 - Missing Authorization to Unauthenticated Shortcode ExecutionEPSS 0.3%CVE-2026-11359MEDIUMMemberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and ActivationEPSS 0.3%CVE-2024-31274MEDIUMWordPress EmbedPress plugin <= 3.9.11 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-8238MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation messageEPSS 0.3%CVE-2025-26983MEDIUMWordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.3 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-9240MEDIUMColissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX actionEPSS 0.3%CVE-2026-55476MEDIUMSnipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin ParameterEPSS 0.3%CVE-2024-7390MEDIUMWP Testimonial Widget <= 3.1 - Missing AuthorizationEPSS 0.3%CVE-2024-31246MEDIUMWordPress PostX plugin <= 3.2.3 - Author+ Post/Page Duplication vulnerabilityEPSS 0.3%CVE-2024-12158MEDIUMPopup – MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Missing Authorization to Unauthenticated DB Table TruncationEPSS 0.3%CVE-2026-12471MEDIUMSpexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin ActivationEPSS 0.3%CVE-2026-4063MEDIUMSocial Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration CreationEPSS 0.3%CVE-2026-30842MEDIUMWallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded AvatarsEPSS 0.3%CVE-2026-12955MEDIUMCookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX ActionEPSS 0.3%CVE-2025-3871MEDIUMBroken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlierEPSS 0.3%CVE-2026-4244MEDIUMPost Duplicator <= 3.0.11 - Missing Authorization to Authenticated (Contributor+) Post Duplication with Arbitrary Author AttributionEPSS 0.3%CVE-2026-3225MEDIUMLearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer DeletionEPSS 0.3%CVE-2024-35729MEDIUMWordPress Tickera plugin <= 3.5.2.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-90533MEDIUMFlowise before 3.1.4 Broken Access Control via organizationuserEPSS 0.3%