Fallos del tipo CWE-284

7085 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2026-37235HIGHFlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation functiEPSS 0.6%CVE-2024-24486CRITICALAn issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA commaEPSS 0.6%CVE-2025-3558MEDIUMghostxbh uzy-ssm-mall uploadUserHeadImage unrestricted uploadEPSS 0.6%CVE-2021-28511MEDIUMThis advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches t ...EPSS 0.6%CVE-2026-2768CRITICALSandbox escape in the Storage: IndexedDB componentEPSS 0.6%CVE-2023-47536LOWAn improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProEPSS 0.6%CVE-2022-3780HIGHDatabase connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deletEPSS 0.6%CVE-2025-28407HIGHAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properEPSS 0.6%CVE-2025-28409HIGHAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properEPSS 0.6%CVE-2026-54408HIGHA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to byEPSS 0.6%CVE-2025-21359HIGHWindows Kernel Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-20706CRITICALGitea repository archive downloads bypass token scope checksEPSS 0.6%CVE-2022-28760MEDIUMZoom On-Premise Deployments: Improper Access ControlEPSS 0.6%CVE-2024-21666MEDIUMPimcore Customer Data Framework Improper Access Control allows unprivileged user to access customers duplicates listEPSS 0.6%CVE-2023-29130CRITICALA vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the coEPSS 0.6%CVE-2026-7686MEDIUMeyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access controlEPSS 0.6%CVE-2021-23178HIGHImproper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online paymentsEPSS 0.6%CVE-2024-42797CRITICALAn Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. ThiEPSS 0.6%CVE-2025-4064MEDIUMScriptAndTools Online-Travling-System viewenquiry.php access controlEPSS 0.6%CVE-2025-64660HIGHGitHub Copilot and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.6%