Fallos del tipo CWE-284

7103 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2025-7538MEDIUMCampcodes Sales and Inventory System product_update.php unrestricted uploadEPSS 0.4%CVE-2025-7470MEDIUMCampcodes Sales and Inventory System product_add.php unrestricted uploadEPSS 0.4%CVE-2025-55373MEDIUMIncorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to escalate privilegesEPSS 0.4%CVE-2022-23994LOWAn Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted EPSS 0.4%CVE-2026-48034HIGHHULUMI-H5 bypass via decoy sibling resources targeting a different bucketEPSS 0.4%CVE-2025-6422MEDIUMCampcodes Online Recruitment Management System About Content Page ajax.php unrestricted uploadEPSS 0.4%CVE-2026-95624MEDIUMTauri framework v2 malicious downgrade via allow_downgrades from frontend codeEPSS 0.4%CVE-2024-1678MEDIUMSubway – Private Site Option <= 2.1.4 - Improper Access Control to Sensitive Information Exposure via REST APIEPSS 0.4%CVE-2026-43713MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS TaEPSS 0.4%CVE-2025-45422HIGHIncorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes EPSS 0.4%CVE-2026-21994CRITICALVulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: EPSS 0.4%CVE-2024-41251MEDIUMAn Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_sEPSS 0.4%CVE-2026-47164HIGHVaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP IdentityEPSS 0.4%CVE-2025-41737HIGHImproper access control via php endpointEPSS 0.4%CVE-2025-49707HIGHAzure Virtual Machines Spoofing VulnerabilityEPSS 0.4%CVE-2026-28862MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.5, macOS SonomEPSS 0.4%CVE-2025-9153MEDIUMitsourcecode Online Tour and Travel Management System travellers.php unrestricted uploadEPSS 0.4%CVE-2026-71102CRITICALVulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21EPSS 0.4%CVE-2025-52101CRITICALlinjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the auEPSS 0.4%CVE-2026-62638CRITICALVulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported EPSS 0.4%