Fallos del tipo CWE-284

7145 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-56050MEDIUMWordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-8859MEDIUMcode-projects eBlog Site File Upload save-slider.php unrestricted uploadEPSS 0.3%CVE-2026-60188MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.3%CVE-2026-0844HIGHSimple User Registration <= 6.7 - Authenticated (Subscriber+) Privilege Escalation via profile_save_fieldEPSS 0.3%CVE-2026-13897HIGHInsufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalatEPSS 0.3%CVE-2024-13693MEDIUMEnfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.phpEPSS 0.3%CVE-2026-13171HIGHEventin < 4.1.20 - Unauthenticated Account Creation via Waiting List EndpointEPSS 0.3%CVE-2025-4281MEDIUMShenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclosureEPSS 0.3%CVE-2024-4263MEDIUMImproper Access Control in mlflow/mlflowEPSS 0.3%CVE-2026-41270HIGHFlowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function SandboxEPSS 0.3%CVE-2025-9841MEDIUMcode-projects Mobile Shop Management System AddNewProduct.php unrestricted uploadEPSS 0.3%CVE-2026-60189MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affeEPSS 0.3%CVE-2023-3096MEDIUMKylinSoft kylin-software-properties changedSource access controlEPSS 0.3%CVE-2026-14829HIGHCheckimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded SecretEPSS 0.3%CVE-2026-46936MEDIUMVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions that are affected areEPSS 0.3%CVE-2025-66911MEDIUMTurms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. TEPSS 0.3%CVE-2022-42862MEDIUMThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may beEPSS 0.3%CVE-2022-42859MEDIUMMultiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOSEPSS 0.3%CVE-2026-70691HIGHVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication InterfaceEPSS 0.3%CVE-2023-47294HIGHAn issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete userEPSS 0.3%