Fallos del tipo CWE-284

7076 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-7198CRITICALCWE-284: Improper Access Control in web services in Progress SitefinityEPSS 0.6%CVE-2021-24500—Workreap theme < 2.2.2 - Multiple CSRF + IDOR VulnerabilitiesEPSS 0.6%CVE-2024-48955HIGHBroken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, theEPSS 0.6%CVE-2016-10549—Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration wEPSS 0.6%CVE-2026-5526MEDIUMTenda 4G03 Pro httpd access controlEPSS 0.6%CVE-2019-5014MEDIUMAn exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.EPSS 0.6%CVE-2023-43696HIGH Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous acceEPSS 0.6%CVE-2025-7565MEDIUMLB-LINK BL-AC3600 Web Management Interface lighttpd.cgi geteasycfg information disclosureEPSS 0.6%CVE-2025-45343CRITICALAn issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module iEPSS 0.6%CVE-2023-7223MEDIUMTotolink T6 cstecgi.cgi access controlEPSS 0.6%CVE-2015-10057MEDIUMLittle Apps Little Software Stats Password Reset class.securelogin.php access controlEPSS 0.6%CVE-2024-45118MEDIUMAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2026-47396CRITICALPraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unsetEPSS 0.6%CVE-2025-32470HIGHUnauthenticated change of IP adressEPSS 0.6%CVE-2025-66390CRITICALIn Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in TenantEPSS 0.6%CVE-2024-46432HIGHTenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setEPSS 0.6%CVE-2022-45431HIGHSome Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access contrEPSS 0.6%CVE-2020-10143HIGHMacrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged seEPSS 0.6%CVE-2026-51770CRITICALIncorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forwEPSS 0.6%CVE-2021-46270LOWJFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repositoryEPSS 0.6%