Fallos del tipo CWE-284

7074 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-49049HIGHJoomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handlerEPSS 1.0%CVE-2017-7497MEDIUMThe dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability toEPSS 1.0%CVE-2024-13108MEDIUMD-Link DIR-816 A2 form2NetSniper.cgi access controlEPSS 1.0%CVE-2018-0119—A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, remote attacker to iEPSS 1.0%CVE-2019-11783MEDIUMImproper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows reEPSS 1.0%CVE-2019-11784MEDIUMImproper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remotEPSS 1.0%CVE-2022-38184HIGHThere is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1EPSS 1.0%CVE-2021-24318—Listeo < 1.6.11 - Multiple Authenticated IDOR VulnerabilitiesEPSS 1.0%CVE-2025-25968MEDIUMDDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitEPSS 1.0%CVE-2019-11895MEDIUMImproper access control in the JSON-RPC interface of the Bosch Smart Home Controller (SHC)EPSS 1.0%CVE-2019-15956HIGHCisco Web Security Appliance Unauthorized Device Reset VulnerabilityEPSS 1.0%CVE-2023-28300HIGHAzure Service Connector Security Feature Bypass VulnerabilityEPSS 1.0%CVE-2023-21751MEDIUMAzure DevOps Server Spoofing VulnerabilityEPSS 1.0%CVE-2025-30693MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0EPSS 1.0%CVE-2019-0036HIGHJunos OS: Firewall filter terms named "internal-1" and "internal-2" being ignoredEPSS 1.0%CVE-2026-50006CRITICALAnyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server ModeEPSS 1.0%CVE-2020-36721MEDIUMEpsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/DeactivationEPSS 1.0%CVE-2019-6144—This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP andEPSS 1.0%CVE-2021-36775HIGHDeleting PRTBs associated to a group doesn't cause deletion of corresponding RoleBindingsEPSS 1.0%CVE-2022-26313—A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations oEPSS 1.0%