Fallos del tipo CWE-285

1587 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-34048CRITICALCoolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team serversEPSS 0.8%CVE-2020-5333MEDIUMRSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated maliciEPSS 0.8%CVE-2023-20088MEDIUMCisco Finesse Reverse Proxy VPN-less Access to Finesse Desktop Denial of Service VulnerabilityEPSS 0.8%CVE-2022-34446HIGH PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limiEPSS 0.8%CVE-2023-2496HIGHGo Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Improper Authorization to Arbitrary File UploadEPSS 0.8%CVE-2017-0927—Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthoEPSS 0.8%CVE-2024-34104HIGHAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.8%CVE-2024-2641MEDIUMRuijie RG-NBS2009G-P Password passwdManage.htm improper authorizationEPSS 0.8%CVE-2022-47553HIGHImproper Authorization in Ormazabal productsEPSS 0.8%CVE-2024-21159MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior anEPSS 0.8%CVE-2023-32022HIGHWindows Server Service Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2023-47109MEDIUMPrestaShop blockreassurance BO User can remove any file from server when adding a and deleting a blockEPSS 0.8%CVE-2022-2019HIGHSourceCodester Prison Management System New User Creation improper authorizationEPSS 0.8%CVE-2020-25716—A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attackEPSS 0.8%CVE-2020-10716—A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw alloEPSS 0.8%CVE-2025-65041CRITICALMicrosoft Partner Center Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-28865HIGHAn authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadEPSS 0.8%CVE-2021-42332MEDIUMShinHer Information Co., LTD. ShinHer StudyOnline System - Improper Authorization-3EPSS 0.8%CVE-2024-8676HIGHCri-o: checkpoint restore can be triggered from different namespacesEPSS 0.8%CVE-2022-4701MEDIUMRoyal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin ActivationEPSS 0.7%