Fallos del tipo CWE-284

7141 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2025-2606MEDIUMSourceCodester Best Church Management Software soulwinning_crud.php unrestricted uploadEPSS 0.3%CVE-2017-12340—A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and CiscEPSS 0.3%CVE-2023-50181MEDIUMAn improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only autEPSS 0.3%CVE-2024-56335HIGHPrivilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwardenEPSS 0.3%CVE-2026-90978HIGHFilter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce CheckEPSS 0.3%CVE-2024-39839MEDIUMRemote username set to an arbitrary string by remote userEPSS 0.3%CVE-2026-40463HIGHAn Insufficient Role-based Access Control Vulnerability in WaveSuiteEPSS 0.3%CVE-2026-60578HIGHVulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported versioEPSS 0.3%CVE-2026-62515HIGHVulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). SupportedEPSS 0.3%CVE-2025-10013MEDIUMPortabilis i-Educar exportacao-para-o-seb access controlEPSS 0.3%CVE-2026-73943HIGHVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are afEPSS 0.3%CVE-2026-61325HIGHVulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version tEPSS 0.3%CVE-2024-13430MEDIUMPage Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcodeEPSS 0.3%CVE-2025-65780HIGHAn issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update theEPSS 0.3%CVE-2026-60270MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.3%CVE-2025-59253MEDIUMWindows Search Service Denial of Service VulnerabilityEPSS 0.3%CVE-2026-60748HIGHVulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that areEPSS 0.3%CVE-2025-70982CRITICALIncorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sEPSS 0.3%CVE-2026-83052HIGHVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are afEPSS 0.3%CVE-2026-87133HIGHVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supportEPSS 0.3%