Fallos del tipo CWE-284

7169 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-54256MEDIUMWinter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadataEPSS 0.2%CVE-2025-13949MEDIUMProudMuBai GoFilm FileController.go SingleUpload unrestricted uploadEPSS 0.2%CVE-2024-57336MEDIUMIncorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to oEPSS 0.2%CVE-2026-47032LOWVulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.EPSS 0.2%CVE-2025-50434MEDIUMA security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is related to incorrecEPSS 0.2%CVE-2025-57219MEDIUMIncorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate priviEPSS 0.2%CVE-2025-55626MEDIUMAn Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662EPSS 0.2%CVE-2020-7253MEDIUMImproper access control vulnerability in McAfee AgentEPSS 0.2%CVE-2026-87262HIGHVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication InterfaceEPSS 0.2%CVE-2022-42327HIGHx86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and wriEPSS 0.2%CVE-2025-36351MEDIUMIBM License Metric Tool bypass securityEPSS 0.2%CVE-2026-49805HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-43495MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be aEPSS 0.2%CVE-2022-27635HIGHImproper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enablEPSS 0.2%CVE-2023-44283HIGH In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concEPSS 0.2%CVE-2026-50325HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-50297HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2024-21805HIGHImproper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If thiEPSS 0.2%CVE-2021-34864HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker EPSS 0.2%CVE-2025-51627MEDIUMIncorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalaEPSS 0.2%