Fallos del tipo CWE-284

7170 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-65361MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app mayEPSS 0.1%CVE-2026-84573MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app mayEPSS 0.1%CVE-2025-45083MEDIUMIncorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspeEPSS 0.1%CVE-2022-40972MEDIUMImproper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable EPSS 0.1%CVE-2025-24323HIGHImproper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before version MR4_1.0b1 maEPSS 0.1%CVE-2026-87280MEDIUMVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2026-82810MEDIUMextension.vn 2FA Authenticator Extension Background Service Worker chrome.runtime.onMessageExternal.addListener information disclosureEPSS 0.1%CVE-2026-50719MEDIUMThe Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header beEPSS 0.1%CVE-2023-21488MEDIUMImproper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.EPSS 0.1%CVE-2026-28993MEDIUMThis issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and EPSS 0.1%CVE-2026-61226HIGHVulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: RTP Proxy). The suppoEPSS 0.1%CVE-2026-35242HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2026-9789HIGHNitroSense V3: Security Vulnerability InformationEPSS 0.1%CVE-2026-60608MEDIUMVulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Institutional Methodology Need AnalysisEPSS 0.1%CVE-2026-15476MEDIUMQILING Disk Master Kernel Driver diskbckp.sys access controlEPSS 0.1%CVE-2026-60159HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2026-60155HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%CVE-2026-71119MEDIUMVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.1%CVE-2026-70712MEDIUMVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version tEPSS 0.1%CVE-2026-35251HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.EPSS 0.1%