Fallos del tipo CWE-284

7169 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-62486MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%CVE-2024-39797MEDIUMImproper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated usEPSS 0.2%CVE-2026-97332MEDIUMUser Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)EPSS 0.2%CVE-2023-23573MEDIUMImproper access control in the Intel(R) Unite(R) android application before Release 17 may allow a privileged user to potentially enable infEPSS 0.2%CVE-2026-60163HIGHVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions EPSS 0.2%CVE-2025-43418MEDIUMThis issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 anEPSS 0.2%CVE-2026-22014LOWVulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versionEPSS 0.2%CVE-2024-36438HIGHeLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to cEPSS 0.2%CVE-2026-12990HIGHMultiple vulnerabilities in Ghost Robotics' Vision 60EPSS 0.2%CVE-2025-44525MEDIUMTexas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient permission checks on criEPSS 0.2%CVE-2026-50132HIGHBudibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account Impersonation in BudibaseEPSS 0.2%CVE-2025-27238LOWAPI hostprototype.get lists data to users with insufficient authorization.EPSS 0.2%CVE-2025-11634LOWTomofun Furbo 360/Furbo Mini UART information disclosureEPSS 0.2%CVE-2025-69284MEDIUMIn plane.io, a Guest User to a Workspace can still be able to see list of membersEPSS 0.2%CVE-2024-24902MEDIUMDell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentEPSS 0.2%CVE-2023-42540MEDIUMImproper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via impEPSS 0.2%CVE-2025-65096MEDIUMRomM Insecure Direct Object Reference (IDOR) Allows Unauthorized Access to Private CollectionsEPSS 0.2%CVE-2022-36441HIGHAn issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use seveEPSS 0.2%CVE-2026-13144LOWWP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment ResetEPSS 0.2%CVE-2025-43332MEDIUMA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.EPSS 0.2%