Fallos del tipo CWE-284

7122 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-1742MEDIUMEFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted uploadEPSS 0.4%CVE-2026-60422CRITICALVulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). The supported version that is affEPSS 0.4%CVE-2026-71163CRITICALVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that EPSS 0.4%CVE-2026-60719CRITICALVulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected areEPSS 0.4%CVE-2026-16547MEDIUMREST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download EndpointEPSS 0.4%CVE-2025-67645HIGHOpenEMR Vulnerable to Broken Access Control in Profile Edit EndpointEPSS 0.4%CVE-2026-2226MEDIUMDouPHP ZIP File file.php unrestricted uploadEPSS 0.4%CVE-2021-1228HIGHCisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized Access VulnerabilityEPSS 0.4%CVE-2025-6466MEDIUMageerle ruoyi-ai SseServiceImpl.java upload unrestricted uploadEPSS 0.4%CVE-2026-55119HIGHA malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk AEPSS 0.4%CVE-2025-63822HIGHSirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parEPSS 0.4%CVE-2022-2995HIGHIncorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible dataEPSS 0.4%CVE-2026-34358HIGHCtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC BypassEPSS 0.4%CVE-2025-59333HIGH@executeautomation/database-server does not properly restrict access, bypassing a "read-only" modeEPSS 0.4%CVE-2026-9604MEDIUMJeecgBoot AiragModelController access controlEPSS 0.4%CVE-2026-18038MEDIUMnextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosureEPSS 0.4%CVE-2024-11484MEDIUMCode4Berry Decoration Management System User Image update_image.php access controlEPSS 0.4%CVE-2026-86285MEDIUMBookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm access controlEPSS 0.4%CVE-2022-45929HIGHNorthern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change EPSS 0.4%CVE-2025-55368HIGHIncorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modifyEPSS 0.4%