Fallos del tipo CWE-284

7078 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2024-57190CRITICALErxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that containEPSS 0.6%CVE-2026-81941HIGHLangflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardsEPSS 0.6%CVE-2025-24968HIGHBusiness Logic And Unrestricted Project Deletion Lead To Take Over the System in reNgineEPSS 0.6%CVE-2025-4977MEDIUMNetgear DGND3700 BRS_top.html information disclosureEPSS 0.6%CVE-2024-0631MEDIUMDuitku Payment Gateway <= 2.11.6 - Missing Authorization via check_duitku_responseEPSS 0.6%CVE-2022-44211HIGHIn GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.EPSS 0.6%CVE-2025-4980MEDIUMNetgear DGND3700 mini_http currentsetting.htm information disclosureEPSS 0.6%CVE-2023-5240—Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAEPSS 0.6%CVE-2025-4271MEDIUMTOTOLINK A720R cstecgi.cgi information disclosureEPSS 0.6%CVE-2022-41970LOWNextcloud Server's disabled download shares still allow download through preview imagesEPSS 0.6%CVE-2022-4567HIGHImproper Access Control in openemr/openemrEPSS 0.6%CVE-2025-48986HIGHAuthorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email addreEPSS 0.6%CVE-2026-51679CRITICALIncorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the EPSS 0.6%CVE-2023-40170MEDIUMcross-site inclusion (XSSI) of files in jupyter-serverEPSS 0.6%CVE-2022-28173CRITICALThe web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permissEPSS 0.6%CVE-2024-31964HIGHA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.6%CVE-2024-21074HIGHVulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Finance LOV). Supported versions that are affecEPSS 0.6%CVE-2025-30710MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected arEPSS 0.6%CVE-2024-42480HIGHKamaji's RBAC Roles for `etcd` are not disjunctEPSS 0.6%CVE-2026-90898CRITICALBifrost unauthenticated remote code execution via MCP stdio client registrationEPSS 0.6%