Fallos del tipo CWE-284

7169 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-62606LOWVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.2%CVE-2026-60351MEDIUMVulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected areEPSS 0.2%CVE-2024-42795MEDIUMAn Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara EPSS 0.2%CVE-2026-16986MEDIUMBooking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost ParametersEPSS 0.2%CVE-2025-70340MEDIUMA Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionaliEPSS 0.2%CVE-2026-75824MEDIUMWP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration DisabledEPSS 0.2%CVE-2026-77765MEDIUMBetter Payment < 2.3.4 - Unauthenticated Payment Amount ManipulationEPSS 0.2%CVE-2023-21969MEDIUMVulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitabEPSS 0.2%CVE-2026-76610MEDIUMJoomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65EPSS 0.2%CVE-2024-42406MEDIUMUnauthorized access on archived channelsEPSS 0.2%CVE-2024-40825MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A malicious app with root privileges may EPSS 0.2%CVE-2021-4016MEDIUMRapid7 Insight Agent Improper Access ControlEPSS 0.2%CVE-2023-38005MEDIUMImproper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]EPSS 0.2%CVE-2024-32939MEDIUMEmail addresses of remote users visible in props regardless of server settingsEPSS 0.2%CVE-2026-11464LOWJeecgBoot User List Endpoint SysUserController.java queryPageList information disclosureEPSS 0.2%CVE-2026-105692MEDIUMPenpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not CreateEPSS 0.2%CVE-2025-12182MEDIUMQi Blocks <= 1.4.3 - Missing Authorization to Arbitrary Attachment ResizeEPSS 0.2%CVE-2023-24485HIGHPrivilege Escalation on the system running a vulnerable version of Citrix Workspace app for WindowsEPSS 0.2%CVE-2021-22682—Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including reaEPSS 0.2%CVE-2025-32992HIGHThermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.EPSS 0.2%