Fallos del tipo CWE-284

7074 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2023-28808CRITICALSome Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. ThEPSS 0.8%CVE-2023-39743—lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.EPSS 0.8%CVE-2023-0451HIGHEconolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and confiEPSS 0.8%CVE-2022-33925MEDIUMDell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could pEPSS 0.8%CVE-2024-13067MEDIUMCodeAstro Online Food Ordering System All Users Page all_users.php access controlEPSS 0.8%CVE-2022-34827HIGHCarel Boss Mini 1.5.0 has Improper Access Control.EPSS 0.8%CVE-2025-7076MEDIUMBlackVue Dashcam 590X Configuration upload.cgi access controlEPSS 0.8%CVE-2023-6930CRITICALImproper Access Control in EuroTel ETL3100EPSS 0.8%CVE-2023-24425MEDIUMJenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentiaEPSS 0.8%CVE-2021-40413HIGHAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_201EPSS 0.8%CVE-2026-75998HIGHColdFusion | Improper Access Control (CWE-284)EPSS 0.8%CVE-2025-55238HIGHDynamics 365 FastTrack Implementation Assets Information Disclosure VulnerabilityEPSS 0.8%CVE-2025-21185MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-46629MEDIUMLack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to performEPSS 0.8%CVE-2025-21587HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). EPSS 0.8%CVE-2025-48983CRITICALA vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructurEPSS 0.8%CVE-2022-31708MEDIUMvRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the ModEPSS 0.8%CVE-2020-7531—A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to plaEPSS 0.8%CVE-2022-3067MEDIUMAn issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versioEPSS 0.8%CVE-2026-73749CRITICALUnauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.8%