Fallos del tipo CWE-284

7123 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2025-37136MEDIUMAuthenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)EPSS 0.4%CVE-2023-46666MEDIUMElastic Sharepoint Online Python Connector Improper Access ControlEPSS 0.4%CVE-2026-22728MEDIUMsealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template annotationsEPSS 0.4%CVE-2025-37135MEDIUMAuthenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)EPSS 0.4%CVE-2025-61115HIGHABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed by ABC Liquors, IncEPSS 0.4%CVE-2025-37137MEDIUMAuthenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)EPSS 0.4%CVE-2025-43027CRITICALA critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attackers to gain adminisEPSS 0.4%CVE-2026-27708HIGHFOSSBilling: IDOR in Servicecustom Client API allows cross-client data accessEPSS 0.4%CVE-2026-83173HIGHVulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are aEPSS 0.4%CVE-2026-1962MEDIUMWeKan Attachment Migration attachmentMigration.js AttachmentMigrationBleed access controlEPSS 0.4%CVE-2026-83044HIGHVulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 1EPSS 0.4%CVE-2026-70855CRITICALVulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported versions that are afEPSS 0.4%CVE-2025-25950HIGHIncorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS)EPSS 0.4%CVE-2019-6744MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung GEPSS 0.4%CVE-2026-83123HIGHVulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.4%CVE-2025-45618MEDIUMIncorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to accEPSS 0.4%CVE-2025-12862MEDIUMprojectworlds Online Notes Sharing Platform userprofile.php unrestricted uploadEPSS 0.4%CVE-2026-1963MEDIUMWeKan Attachment Storage attachments.js MoveStorageBleed access controlEPSS 0.4%CVE-2025-64110HIGHCursor: Authentication Bypass Possible via New Cursorignore WriteEPSS 0.4%CVE-2026-83143HIGHVulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing). Supported versions that are affectedEPSS 0.4%