Fallos del tipo CWE-284

7169 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-62580LOWVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is aEPSS 0.2%CVE-2025-65097HIGHInsecure Direct Object Reference (IDOR) Allows Unauthorized Deletion of User CollectionsEPSS 0.2%CVE-2024-41309HIGHAn issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gaEPSS 0.2%CVE-2026-12212MEDIUMhcengineering Huly Platform RPC operations.ts getMailboxSecret access controlEPSS 0.2%CVE-2022-34672HIGHNVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the secuEPSS 0.2%CVE-2026-10172MEDIUMBdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadEPSS 0.2%CVE-2023-20065HIGHA vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevEPSS 0.2%CVE-2021-33162HIGHImproper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authentEPSS 0.2%CVE-2026-10152MEDIUMTaleLin lin-cms-spring-boot book Endpoint BookController.java access controlEPSS 0.2%CVE-2025-55012HIGHZed AI Agent Remote Code ExecutionEPSS 0.2%CVE-2024-30146MEDIUMHCL Domino Leap is affected by improper access controlEPSS 0.2%CVE-2026-48529MEDIUMGitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusionEPSS 0.2%CVE-2023-7025HIGHKylinSoft hedron-domain-hook DBus init_kcm access controlEPSS 0.2%CVE-2022-34457HIGH Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secureEPSS 0.2%CVE-2023-40071HIGHImproper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enableEPSS 0.2%CVE-2026-0977MEDIUMIBM CICS Transaction Gateway for Multiplatforms Information DisclosureEPSS 0.2%CVE-2025-25730MEDIUMAn issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorizEPSS 0.2%CVE-2024-1898LOWImproper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notEPSS 0.2%CVE-2026-16387CRITICALSite isolation issue in the Networking componentEPSS 0.2%CVE-2025-43407HIGHThis issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS SeEPSS 0.2%