Fallos del tipo CWE-284

7070 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2023-41772HIGHWin32k Elevation of Privilege VulnerabilityEPSS 11.8%CVE-2025-3663MEDIUMTOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access controlEPSS 11.3%CVE-2026-33478CRITICALAVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command InjectionEPSS 11.2%CVE-2022-20780CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 11.2%CVE-2022-20777CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 11.1%CVE-2025-2993MEDIUMTenda FH1202 default.cfg access controlEPSS 10.9%CVE-2018-10630—For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication diEPSS 10.9%CVE-2025-2546MEDIUMD-Link DIR-618/DIR-605L Firewall Service formAdvFirewall access controlEPSS 10.8%CVE-2024-1675HIGHInsufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictiEPSS 10.6%CVE-2022-20779CRITICALCisco Enterprise NFV Infrastructure Software VulnerabilitiesEPSS 10.5%CVE-2023-28810MEDIUMSome access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify dEPSS 10.4%CVE-2018-7364HIGHAll versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due tEPSS 10.3%CVE-2023-26347HIGHCVE-2023-38205 issues | ColdFusion Admin Panel AccessEPSS 10.1%CVE-2025-48999MEDIUMDataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE VulnerabilityEPSS 10.0%CVE-2021-24215—Controlled Admin Access < 1.5.2 - Improper Access Control & Privilege EscalationEPSS 9.7%CVE-2026-35616CRITICALA improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauEPSS 9.1%KEVCVE-2022-1631MEDIUMUsers Account Pre-Takeover or Users Account Takeover. in microweber/microweberEPSS 8.8%CVE-2017-12171MEDIUMA regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuratEPSS 8.1%CVE-2019-11634CRITICALCitrix Workspace App before 1904 for Windows has Incorrect Access Control.EPSS 8.0%KEVCVE-2018-15640HIGHImproper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated prEPSS 7.8%