Fallos del tipo CWE-284

7167 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-75793MEDIUMSureCart < 4.7.0 - Unauthenticated Account Creation with Automatic LoginEPSS 0.3%CVE-2026-77695MEDIUMWoo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and ManipulationEPSS 0.3%CVE-2024-44303HIGHThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify proteEPSS 0.3%CVE-2026-12688MEDIUMProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN ForgeryEPSS 0.3%CVE-2026-42862HIGHFlowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource ReassignmentEPSS 0.3%CVE-2026-77010MEDIUMHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Join URL Disclosure and Class Access Code BypassEPSS 0.3%CVE-2026-34312LOWVulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulEPSS 0.3%CVE-2025-0744HIGHImproper Access Control vulnerability in EmbedAIEPSS 0.3%CVE-2026-14834MEDIUMMailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAXEPSS 0.3%CVE-2026-86812MEDIUMWPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST APIEPSS 0.3%CVE-2026-14315MEDIUMPixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event SubmissionEPSS 0.3%CVE-2026-101146MEDIUMEleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosureEPSS 0.3%CVE-2024-5270MEDIUMSAML to email switch possible when email signin is disabledEPSS 0.3%CVE-2024-0104MEDIUMNVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause impropeEPSS 0.3%CVE-2026-48956MEDIUMJoomla! Core - [20260710] - Incorrect Access Control in com_modulesEPSS 0.3%CVE-2025-50897MEDIUMA vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translationsEPSS 0.3%CVE-2026-83085HIGHVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that EPSS 0.3%CVE-2025-10741MEDIUMSelleo Mentingo Profile Picture unrestricted uploadEPSS 0.3%CVE-2024-30148MEDIUMHCL Leap is affected by improper access controlEPSS 0.3%CVE-2026-20322CRITICALCisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access ControlEPSS 0.3%