Fallos del tipo CWE-284

7074 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2022-39406HIGHVulnerability in the PeopleSoft Enterprise Common Components product of Oracle PeopleSoft (component: Approval Framework). The supported verEPSS 0.7%CVE-2025-0582MEDIUMitsourcecode Farm Management System add-pig.php unrestricted uploadEPSS 0.7%CVE-2026-2684MEDIUMTsinghua Unigroup Electronic Archives System uploadFile.html unrestricted uploadEPSS 0.7%CVE-2023-24028CRITICALIn MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.EPSS 0.7%CVE-2019-11786MEDIUMImproper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modifyEPSS 0.7%CVE-2026-35425HIGHAzure API Management (APIM) Remote Code Execution VulnerabilityEPSS 0.7%CVE-2021-34627MEDIUMWP Upload Restriction <= 2.2.3 - Missing Access Control in getSelectedMimeTypesByRole functionEPSS 0.7%CVE-2026-26145MEDIUMMicrosoft Azure Synapse Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2021-4364MEDIUMJobSearch WP Job Board < = 1.8.1 - Missing Authorization on jobsearch_update_job_import_schedule_call() functionEPSS 0.7%CVE-2022-39310MEDIUMMalicious agent may be able to impersonate another agent in GoCDEPSS 0.7%CVE-2026-2983MEDIUMSourceCodester Student Result Management System Bulk Import import_users.php access controlEPSS 0.7%CVE-2023-24688MEDIUMAn issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is diEPSS 0.7%CVE-2021-4089MEDIUMImproper Access Control in snipe/snipe-itEPSS 0.7%CVE-2025-15082MEDIUMTOZED ZLT M30s Web Management proc_post information disclosureEPSS 0.7%CVE-2026-26325HIGHOpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvalsEPSS 0.7%CVE-2022-46354MEDIUMA vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALAEPSS 0.7%CVE-2025-43184CRITICALThis issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.7, maEPSS 0.7%CVE-2022-40036MEDIUMAn issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via EPSS 0.7%CVE-2023-2901MEDIUMNFine Rapid Development Platform access controlEPSS 0.7%CVE-2025-50900CRITICALAn issue was discovered in getrebuild/rebuild 4.0.4. The affected source code class is com.rebuild.web.RebuildWebInterceptor, and the affectEPSS 0.7%