Weaknesses of type CWE-862

8,835 results

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para fazê-lo. É a brecha clássica onde o código autentifica (sabe quem é) mas não autoriza (valida se pode). Resultado: usuários comuns acessam dados sensíveis ou administrativos.

Example

Um sistema de e-commerce autentica o cliente, mas ao acessar /pedidos/123, não verifica se o pedido pertence àquele usuário — qualquer cliente logado vê qualquer pedido alheio. Ou um painel administrativo expõe endpoints que deleta contas, mas qualquer conta logada consegue chamar.

How to mitigate

Implemente verificação de autorização em todo endpoint ou ação sensível: valide não só identidade, mas permissões (roles, ACLs, policies). Use middleware ou decoradores (@RequireRole, @Authorize) e teste cenários onde usuários com privileégio baixo tentam acessar recursos alheios ou funções restritas.

CVE-2026-22492MEDIUMWordPress Docket Cache plugin <= 24.07.04 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-67970MEDIUMWordPress Schedula plugin <= 1.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-13692MEDIUMPayU CommercePro < 3.9.0 - Unauthenticated Order TamperingEPSS 0.3%CVE-2026-82267MEDIUMKomodo Resource Identifier Disclosure and Audit Log Pollution Before Permission CheckEPSS 0.3%CVE-2026-44794MEDIUMNautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to referenceEPSS 0.3%CVE-2026-4056MEDIUMUser Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule ManipulationEPSS 0.3%CVE-2026-17021MEDIUMSalon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total TamperingEPSS 0.3%CVE-2026-18777MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_statusEPSS 0.3%CVE-2026-77701MEDIUMWCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest OrdersEPSS 0.3%CVE-2025-31469MEDIUMWordPress Clear Sucuri Cache plugin <= 1.4 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2023-46203MEDIUMWordPress Just Custom Fields plugin <= 3.3.2 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-100617HIGHCap-go capgo.app Authorization Bypass via channel_permission_overridesEPSS 0.3%CVE-2025-13318MEDIUMBooking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' ParameterEPSS 0.3%CVE-2024-13312MEDIUMOpen Social - Moderately critical - Access bypass - SA-CONTRIB-2024-076EPSS 0.3%CVE-2026-67233MEDIUMRabbitMQ: Monitoring-tag user can DELETE shovelsEPSS 0.3%CVE-2026-95297MEDIUMMissing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via EPSS 0.3%CVE-2025-43358HIGHA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 2EPSS 0.3%CVE-2026-53626HIGHGLPI: Arbitrary Document Read via Form Context Authorization BypassEPSS 0.3%CVE-2026-0814MEDIUMAdvanced CF7 DB <= 2.0.9 - Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel ExportEPSS 0.3%CVE-2024-13737MEDIUMMotors – Car Dealer, Classifieds & Listing <= 1.4.57 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Listing Template CreationEPSS 0.3%