Fallos del tipo CWE-284

7088 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2025-31698HIGHApache Traffic Server: Client IP address from PROXY protocol is not used for ACLEPSS 0.6%CVE-2025-59500HIGHAzure Notification Service Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2022-32834MEDIUMAn access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security UEPSS 0.6%CVE-2023-51070HIGHAn access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjusEPSS 0.6%CVE-2025-1834MEDIUMzj1983 zz resolve unrestricted uploadEPSS 0.6%CVE-2025-0346MEDIUMcode-projects Content Management System Publish News Page publishnews.php unrestricted uploadEPSS 0.6%CVE-2023-21905MEDIUMVulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). EPSS 0.6%CVE-2026-2666MEDIUMmingSoft MCMS Template Archive uploadTemplate.do unrestricted uploadEPSS 0.6%CVE-2024-45122MEDIUMAdobe Commerce | Improper Access Control (CWE-284)EPSS 0.6%CVE-2024-36080CRITICALWestermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is EPSS 0.6%CVE-2026-28699HIGHGitea Basic Auth bypasses OAuth2 access token scopesEPSS 0.6%CVE-2025-66430CRITICALPlesk 18.0 has Incorrect Access Control.EPSS 0.6%CVE-2024-42559CRITICALAn issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providEPSS 0.6%CVE-2024-38873MEDIUMAn issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extensioEPSS 0.5%CVE-2022-21586MEDIUMVulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supportEPSS 0.5%CVE-2022-46676MEDIUM Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users unEPSS 0.5%CVE-2022-47037HIGHSiklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.EPSS 0.5%CVE-2026-86284MEDIUMjaychouchannel Tourism-Management-System CommonController.java getOption information disclosureEPSS 0.5%CVE-2022-46677MEDIUM Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroupEPSS 0.5%CVE-2026-44774MEDIUMTraefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=falseEPSS 0.5%