Fallos del tipo CWE-284

7169 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-28945HIGHA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, maEPSS 0.2%CVE-2026-92223MEDIUMJoomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3EPSS 0.2%CVE-2026-12786HIGHEzbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access controlEPSS 0.2%CVE-2024-36488MEDIUMImproper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of prEPSS 0.2%CVE-2026-19195HIGHV-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access controlEPSS 0.2%CVE-2026-12779HIGHAOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access controlEPSS 0.2%CVE-2026-89190MEDIUMRobin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajaxEPSS 0.2%CVE-2026-21848MEDIUMHCL BigFix Service Management is affected by multiple security vulnerabilities.EPSS 0.2%CVE-2026-12784HIGHIM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access controlEPSS 0.2%CVE-2025-43309LOWA logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical access to an iOS deEPSS 0.2%CVE-2026-28682MEDIUMGokapi: Data Leak in Upload Status StreamEPSS 0.2%CVE-2026-19193HIGHJiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access controlEPSS 0.2%CVE-2023-44292MEDIUM Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileEPSS 0.2%CVE-2023-44282MEDIUM Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileEPSS 0.2%CVE-2026-20642LOWAn input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device mayEPSS 0.2%CVE-2026-84535HIGHAn authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS EPSS 0.2%CVE-2026-35243HIGHVulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported vEPSS 0.2%CVE-2026-61291HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-71051HIGHVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported verEPSS 0.2%CVE-2026-82992HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected areEPSS 0.2%