Fallos del tipo CWE-284

7168 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-73885HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-73875HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-17023MEDIUMSalon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth CallbackEPSS 0.3%CVE-2026-60521MEDIUMVulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affectEPSS 0.3%CVE-2022-39910LOWImproper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on aEPSS 0.3%CVE-2026-71032HIGHVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca ApplicEPSS 0.3%CVE-2026-73897MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-23782HIGHAn issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both aEPSS 0.3%CVE-2026-60866MEDIUMVulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version tEPSS 0.3%CVE-2026-73904MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-61262MEDIUMVulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions thaEPSS 0.3%CVE-2026-46980MEDIUMVulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mobile). Supported verEPSS 0.3%CVE-2026-79201MEDIUMImproper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a craftEPSS 0.3%CVE-2026-20167HIGHCisco IoT Field Network Director Remote Device Denial of Service VulnerabilityEPSS 0.3%CVE-2026-21954MEDIUMVulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supportedEPSS 0.3%CVE-2026-70788MEDIUMVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affEPSS 0.3%CVE-2026-73886HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-73868MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.3%CVE-2026-46810MEDIUMVulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported versions that are aEPSS 0.3%CVE-2026-95263HIGHFeehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can chEPSS 0.3%