Weaknesses of type CWE-862

9,009 results

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para fazê-lo. É a brecha clássica onde o código autentifica (sabe quem é) mas não autoriza (valida se pode). Resultado: usuários comuns acessam dados sensíveis ou administrativos.

Example

Um sistema de e-commerce autentica o cliente, mas ao acessar /pedidos/123, não verifica se o pedido pertence àquele usuário — qualquer cliente logado vê qualquer pedido alheio. Ou um painel administrativo expõe endpoints que deleta contas, mas qualquer conta logada consegue chamar.

How to mitigate

Implemente verificação de autorização em todo endpoint ou ação sensível: valide não só identidade, mas permissões (roles, ACLs, policies). Use middleware ou decoradores (@RequireRole, @Authorize) e teste cenários onde usuários com privileégio baixo tentam acessar recursos alheios ou funções restritas.

CVE-2026-100525MEDIUMOpenClaw diagnostics-prometheus before 2026.9.3 Authentication BypassEPSS 0.2%CVE-2023-35998MEDIUMITM Server Missing Authorization in SOAP EndpointsEPSS 0.2%CVE-2025-66154MEDIUMWordPress Couponer for Elementor plugin <= 1.1.7 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-93580MEDIUMInPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment WebhookEPSS 0.2%CVE-2026-97311MEDIUMKeycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorizationEPSS 0.2%CVE-2026-24362MEDIUMWordPress Ultimate Post Kit plugin <= 4.0.21 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-66158MEDIUMWordPress Gmaper for Elementor plugin <= 1.0.9 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-66155MEDIUMWordPress Questionar for Elementor plugin <= 1.1.7 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-66159MEDIUMWordPress Walker for Elementor plugin <= 1.1.6 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-12165MEDIUMWebcake – Landing Page Builder <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Settings UpdateEPSS 0.2%CVE-2025-42899MEDIUMMissing Authorization check in SAP S4CORE (Manage Journal Entries)EPSS 0.2%CVE-2025-66157MEDIUMWordPress Sliper for Elementor plugin <= 1.0.10 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-95320MEDIUMMissing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proceEPSS 0.2%CVE-2025-66156MEDIUMWordPress Watcher for Elementor plugin <= 1.0.9 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-11355MEDIUMDT LMS <= 1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via Multiple AJAX ActionsEPSS 0.2%CVE-2026-101047MEDIUMFleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLsEPSS 0.2%CVE-2023-41656MEDIUMWordPress Better Elementor Addons plugin <= 1.3.7 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-102310MEDIUMMissing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer processEPSS 0.2%CVE-2026-87498LOWMissing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process toEPSS 0.2%CVE-2024-58337HIGHAkuvox Smart Intercom S539 Improper Access Control via ServicesHTTPAPIEPSS 0.2%