Fallos del tipo CWE-284

7169 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2025-47792MEDIUMNextcloud Desktop 3rdparty applications can create share links via socket APIEPSS 0.2%CVE-2026-11252MEDIUMInsufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionarEPSS 0.2%CVE-2023-20260MEDIUMA vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticEPSS 0.2%CVE-2026-21711MEDIUMA flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission cheEPSS 0.2%CVE-2026-11274MEDIUMInappropriate implementation in DOM Distiller in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation EPSS 0.2%CVE-2024-41926LOWMalicious remote can claim that a user was synced from another remoteEPSS 0.2%CVE-2026-35247MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-71115MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2023-44248MEDIUMAn improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all mEPSS 0.2%CVE-2024-54559MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.EPSS 0.2%CVE-2026-56657MEDIUMGitea SSH Key Parser Denial of ServiceEPSS 0.2%CVE-2026-71114MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.2%CVE-2026-73880MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.2%CVE-2026-60265MEDIUMVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.2%CVE-2026-65380MEDIUMAn issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden GEPSS 0.2%CVE-2026-19245MEDIUMHKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosureEPSS 0.2%CVE-2026-56755MEDIUMDenial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package UploadEPSS 0.2%CVE-2024-54565MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.EPSS 0.2%CVE-2023-30768HIGHImproper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 00EPSS 0.2%CVE-2023-31199HIGHImproper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user to potentially enableEPSS 0.2%