Fallos del tipo CWE-1220

115 resultados

Controle de acesso com granularidade insuficiente

A aplicação implementa controle de acesso, mas em nível muito grosseiro — por exemplo, libera acesso a um módulo inteiro quando deveria controlar operações específicas dentro dele. Assim, um usuário autorizado a ler dados consegue também deletá-los ou modificá-los, ampliando indevidamente suas permissões.

Ejemplo

Um painel administrativo verifica se o usuário é 'gerente', mas não valida se esse gerente pode apagar usuários específicos ou apenas consultá-los. O atacante autenticado como gerente executa operações não permitidas porque a verificação foi feita só no acesso ao módulo, não em cada ação.

Cómo mitigar

Implemente controle de acesso por atributo ou papel (RBAC/ABAC) que valide permissões em cada operação sensível, não apenas na entrada do módulo. Use listas de controle de acesso (ACL) específicas para cada recurso e ação (criar, ler, atualizar, deletar).

CVE-2023-32259MEDIUMPotential Insufficient Access Control vulnerability has been identified in OpenText™ SMAX/AMX products.EPSS 0.3%CVE-2025-2408MEDIUMInsufficient Granularity of Access Control in GitLabEPSS 0.3%CVE-2026-14613MEDIUMKeycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permissionEPSS 0.3%CVE-2025-54461MEDIUMChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited, an uninvited guestEPSS 0.3%CVE-2026-78122HIGHdocker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container FilesystemsEPSS 0.3%CVE-2024-11931MEDIUMInsufficient Granularity of Access Control in GitLabEPSS 0.3%CVE-2026-86338MEDIUMAsh field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracleEPSS 0.3%CVE-2025-20111HIGHCisco Nexus 3000 and 9000 Series Switches Layer 2 Ethernet Denial of Service VulnerabilityEPSS 0.3%CVE-2026-14615MEDIUMKeycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child view permission filterEPSS 0.3%CVE-2025-1110LOWInsufficient Granularity of Access Control in GitLabEPSS 0.3%CVE-2025-5982LOWInsufficient Granularity of Access Control in GitLabEPSS 0.3%CVE-2026-48581HIGHSurface Broker SDMA Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-49170HIGHWindows StateRepository API Server file Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50405HIGHWindows Filtering Platform Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-55006HIGHMicrosoft Exchange Server Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-6356CRITICALCVE-2026-6356EPSS 0.3%CVE-2025-54518HIGHImproper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructionEPSS 0.3%CVE-2025-20305MEDIUMA vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive informaEPSS 0.3%CVE-2025-8049LOWInsufficient Access Control vulnerability has been discovered in OpenText Flipper.EPSS 0.3%CVE-2024-12619MEDIUMInsufficient Granularity of Access Control in GitLabEPSS 0.3%