Fallos del tipo CWE-284

7079 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2025-58752LOWVite's `server.fs` settings were not applied to HTML filesEPSS 0.6%CVE-2023-33946LOWThe Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in differenEPSS 0.6%CVE-2025-5409MEDIUMMist Community Edition API Token views.py create_token access controlEPSS 0.6%CVE-2023-21531HIGHAzure Service Fabric Container Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-63225CRITICALThe Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critEPSS 0.6%CVE-2025-8226MEDIUMyanyutao0402 ChanCMS find information disclosureEPSS 0.6%CVE-2022-4684HIGHImproper Access Control in usememos/memosEPSS 0.6%CVE-2026-75338CRITICALdisconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/confEPSS 0.6%CVE-2022-24038MEDIUMUnauthorized modification in Karmasis Informatics Infraskope SIEM+EPSS 0.6%CVE-2021-36913HIGHRedirection for Contact Form 7 <= 2.4.0 - Unauthenticated Options Change and Content Injection vulnerabilityEPSS 0.6%CVE-2023-43119—An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to EPSS 0.6%CVE-2024-45124MEDIUMAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2023-21860MEDIUMVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations). Supported versions that are affected EPSS 0.6%CVE-2023-27088HIGHfeiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform EPSS 0.6%CVE-2021-42360HIGHStarter Templates — Elementor, Gutenberg & Beaver Builder Templates <= 2.7.0 Authenticated Block Import to Stored XSSEPSS 0.6%CVE-2024-42967CRITICALIncorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains thEPSS 0.6%CVE-2022-4709MEDIUMRoyal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit ImportEPSS 0.6%CVE-2022-4708MEDIUMRoyal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions ModificationEPSS 0.6%CVE-2026-21535HIGHMicrosoft Teams Information Disclosure VulnerabilityEPSS 0.6%CVE-2022-4705MEDIUMRoyal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template ActivationEPSS 0.6%