Fallos del tipo CWE-284

7078 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-54745CRITICALKubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=trueEPSS 0.6%CVE-2023-0811CRITICAL Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a EPSS 0.6%CVE-2026-90898CRITICALBifrost unauthenticated remote code execution via MCP stdio client registrationEPSS 0.6%CVE-2022-46892CRITICALIn Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.EPSS 0.6%CVE-2025-29515CRITICALIncorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modiEPSS 0.6%CVE-2022-43977CRITICALAn issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn sEPSS 0.6%CVE-2022-47699CRITICALCOMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control.EPSS 0.6%CVE-2025-0206MEDIUMcode-projects Online Shoe Store index.php access controlEPSS 0.6%CVE-2022-44212MEDIUMIn GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.EPSS 0.6%CVE-2023-28844MEDIUMUser without download rights can download older version of that file in nextcloud serverEPSS 0.6%CVE-2020-27873MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1EPSS 0.6%CVE-2026-51754CRITICALIncorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwritEPSS 0.6%CVE-2023-47031CRITICALAn issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsersEPSS 0.6%CVE-2022-31055HIGHImproper Access Control in kctfEPSS 0.6%CVE-2026-52844HIGHCaddy: Windows `file_server` path authorization bypass via encoded backslashEPSS 0.6%CVE-2022-38546MEDIUMA DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker EPSS 0.6%CVE-2025-3675MEDIUMTOTOLINK A3700R cstecgi.cgi setL2tpServerCfg access controlEPSS 0.6%CVE-2025-3237MEDIUMTenda FH1202 wrlwpsset access controlEPSS 0.6%CVE-2026-51689CRITICALIncorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmwEPSS 0.6%CVE-2022-2702HIGHSourceCodester Company Website CMS Cookie site-settings.php access controlEPSS 0.6%