Fallos del tipo CWE-284

7169 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-61260MEDIUMVulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are EPSS 0.2%CVE-2026-60310MEDIUMVulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are EPSS 0.2%CVE-2026-47001MEDIUMVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Web Services Framework). SuppEPSS 0.2%CVE-2026-83488MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported versions that are afEPSS 0.2%CVE-2026-13736MEDIUMNewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST APIEPSS 0.2%CVE-2026-61263MEDIUMVulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions that are affectedEPSS 0.2%CVE-2026-73913MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.2%CVE-2026-60724MEDIUMVulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versionsEPSS 0.2%CVE-2026-77320MEDIUMTREK: Public trip share link ignores the `share_map` permission server-side (client-enforced authorization → itinerary/location disclosure)EPSS 0.2%CVE-2026-61075MEDIUMVulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported verEPSS 0.2%CVE-2026-60912MEDIUMVulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that aEPSS 0.2%CVE-2026-62482MEDIUMVulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versionEPSS 0.2%CVE-2026-60717MEDIUMVulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). SuppEPSS 0.2%CVE-2026-60154MEDIUMVulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are afEPSS 0.2%CVE-2026-61152MEDIUMVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience MaEPSS 0.2%CVE-2026-62441MEDIUMVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.2%CVE-2026-61200MEDIUMVulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions thatEPSS 0.2%CVE-2026-84385MEDIUMA improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7EPSS 0.2%CVE-2026-9522MEDIUMImproper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user withouEPSS 0.2%CVE-2026-23522LOWLobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File DeletionEPSS 0.2%