Weaknesses of type CWE-863

3,052 results

Falha em Controle de Acesso

A aplicação implementa uma verificação de permissões, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que deveria estar impedido de fazer. O problema é que o desenvolvedor assume (errado) que a autenticação é suficiente, não valida o contexto da requisição ou implementa a autorização de forma frágil — por exemplo, verificando apenas o ID do usuário em um parâmetro sem validar no servidor, ou deixando lacunas em condições lógicas.

Example

Um painel administrativo verifica se o usuário está logado, mas não confirma se é realmente um admin antes de exibir a página de configurações. Um usuário comum consegue acessar a URL /admin/settings e alterar parâmetros críticos porque o backend apenas confere a sessão ativa, não o papel atribuído. Ou um e-commerce valida se o ID do pedido existe, mas não confirma se pertence ao usuário autenticado — qualquer um consegue visualizar ou cancelar pedidos alheios.

How to mitigate

Implemente verificações de autorização consistentes no servidor para cada ação sensível: confirme não apenas que o usuário está autenticado, mas que ele tem permissão explícita (role, escopo, proprietário do recurso). Use uma lista branca de ações permitidas, nunca lista negra. Teste a autorização com contas de diferentes perfis e tente contornar as verificações alterando parâmetros ou sessões.

CVE-2026-9807MEDIUMIncorrect Authorization in GitLabEPSS 0.3%CVE-2026-55499MEDIUMCloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipientsEPSS 0.3%CVE-2026-63309MEDIUMSurrealDB < 3.1.5 Information Disclosure via ORDER BYEPSS 0.3%CVE-2026-46635MEDIUMTwig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)EPSS 0.3%CVE-2026-77786MEDIUMRank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo AbilityEPSS 0.3%CVE-2021-3469—Foreman versions before 2.3.4 and before 2.4.0 is affected by an improper authorization handling flaw. An authenticated attacker can impersoEPSS 0.3%CVE-2024-36364MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisherEPSS 0.3%CVE-2024-36376MEDIUMIn JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissionsEPSS 0.3%CVE-2025-30743HIGHVulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). The supporteEPSS 0.3%CVE-2024-49808MEDIUMIBM Sterling Connect:Direct Web Services improper authorizationEPSS 0.3%CVE-2026-86490MEDIUMIn JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpointEPSS 0.3%CVE-2023-26244HIGHAn issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, EPSS 0.3%CVE-2023-26245HIGHAn issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, wEPSS 0.3%CVE-2024-36377MEDIUMIn JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissionsEPSS 0.3%CVE-2025-30744HIGHVulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors). Supported versiEPSS 0.3%CVE-2026-24428HIGHTenda W30E V2 Incorrect Authorization Allows Administrator Password ChangeEPSS 0.3%CVE-2023-26246HIGHAn issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, wEPSS 0.3%CVE-2025-41030MEDIUMMultiple vulnerabilities in Deporsite by T-INNOVAEPSS 0.3%CVE-2026-48508HIGHLemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermissionEPSS 0.3%CVE-2023-32967MEDIUMQTS, QuTScloudEPSS 0.3%