Fallos del tipo CWE-284

7074 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2025-24259CRITICALThis issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, EPSS 0.8%CVE-2023-1862HIGHRemote access to warp-svc.exe in Cloudflare WARPEPSS 0.8%CVE-2022-31257—A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (AllEPSS 0.8%CVE-2025-63223CRITICALThe Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authEPSS 0.8%CVE-2025-43232CRITICALA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS VenturEPSS 0.8%CVE-2025-3790MEDIUMbaseweb JSite Apache Druid Monitoring Console index.html access controlEPSS 0.8%CVE-2026-39006CRITICALAn issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.EPSS 0.8%CVE-2024-49044MEDIUMVisual Studio Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2014-8183HIGHIt was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An atEPSS 0.7%CVE-2025-54603CRITICALAn incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonationEPSS 0.7%CVE-2022-23241HIGHClustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allEPSS 0.7%CVE-2022-41652MEDIUMWordPress Quiz And Survey Master plugin <= 7.3.10 - Bypass vulnerabilityEPSS 0.7%CVE-2022-24924LOWAn improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a prEPSS 0.7%CVE-2021-41543—A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V1EPSS 0.7%CVE-2022-44014MEDIUMAn issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQLEPSS 0.7%CVE-2023-30587HIGHA vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspectEPSS 0.7%CVE-2018-15372—Cisco IOS XE Software MACsec MKA Using EAP-TLS Authentication Bypass VulnerabilityEPSS 0.7%CVE-2026-75465HIGHThe /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails toEPSS 0.7%CVE-2023-2903MEDIUMNFine Rapid Development Platform access controlEPSS 0.7%CVE-2023-28645MEDIUMSecure view can be bypassed by using internal API endpoint in Nextcloud richdocumentsEPSS 0.7%