Weaknesses of type CWE-862

8,853 results

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para fazê-lo. É a brecha clássica onde o código autentifica (sabe quem é) mas não autoriza (valida se pode). Resultado: usuários comuns acessam dados sensíveis ou administrativos.

Example

Um sistema de e-commerce autentica o cliente, mas ao acessar /pedidos/123, não verifica se o pedido pertence àquele usuário — qualquer cliente logado vê qualquer pedido alheio. Ou um painel administrativo expõe endpoints que deleta contas, mas qualquer conta logada consegue chamar.

How to mitigate

Implemente verificação de autorização em todo endpoint ou ação sensível: valide não só identidade, mas permissões (roles, ACLs, policies). Use middleware ou decoradores (@RequireRole, @Authorize) e teste cenários onde usuários com privileégio baixo tentam acessar recursos alheios ou funções restritas.

CVE-2025-10040HIGHWP Import – Ultimate CSV XML Importer for WordPress <= 7.27 - Missing Authorization to Authenticated (Subscriber+) FTP/SFTP Credential ExposureEPSS 0.3%CVE-2026-26979NONEDiscourse: TL4 users are able to change status of restricted topicsEPSS 0.3%CVE-2024-48898MEDIUMMoodle: some users can delete audiences of other reportsEPSS 0.3%CVE-2025-60086HIGHWordPress WP Voting Contest plugin <= 5.8 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-5309MEDIUMForm Vibes – Database Manager for Forms <= 1.4.12 - Missing Authorization in Multiple FunctionsEPSS 0.3%CVE-2022-47425MEDIUMWordPress ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin <= 3.4.10 - Broken Access ControlEPSS 0.3%CVE-2026-87534MEDIUMMissing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineeriEPSS 0.3%CVE-2025-14455MEDIUMImage Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor+) Gallery ManagementEPSS 0.3%CVE-2026-43696MEDIUMAn authorization issue was addressed with improved entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to caEPSS 0.3%CVE-2024-41624MEDIUMIncorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspecified impact.EPSS 0.3%CVE-2025-1745MEDIUMLinZhaoguan pb-cms Logout cross-site request forgeryEPSS 0.3%CVE-2024-13686MEDIUMVW Storefront <= 0.9.9 - Missing Authorization to Authenticated (Subscriber+) Settings ResetEPSS 0.3%CVE-2020-27349—aptdaemon performed policykit permissions checks too lateEPSS 0.3%CVE-2025-14782MEDIUMForminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV ExportEPSS 0.3%CVE-2024-13651MEDIUMRapidLoad – Optimize Web Vitals Automatically <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Limited Setting ResetEPSS 0.3%CVE-2025-3687MEDIUMmisstt123 oasys Sticky Notes cross-site request forgeryEPSS 0.3%CVE-2026-81915MEDIUMIn Concrete CMS below 9.5.3, Page Type update omits object-level authorizationEPSS 0.3%CVE-2024-4341MEDIUMIDOR in ExtremePacs's Extreme XDSEPSS 0.3%CVE-2025-49860MEDIUMWordPress Majestic Support plugin <= 1.1.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-76251HIGHMissing Authorization through REST API Endpoints in the Splunk App for Splunk Observability CloudEPSS 0.3%