Fallos del tipo CWE-285

1588 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2019-3641MEDIUMExploitation of Authorization in TIE ServerEPSS 0.7%CVE-2025-24053HIGHMicrosoft Dataverse Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2024-56320CRITICALGoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated userEPSS 0.7%CVE-2025-2345CRITICALIROAD Dash Cam X5/Dash Cam X6 improper authorizationEPSS 0.7%CVE-2022-4688HIGHImproper Authorization in usememos/memosEPSS 0.7%CVE-2022-0821HIGHImproper Authorization in orchardcms/orchardcoreEPSS 0.7%CVE-2024-47053HIGHImproper Authorization in Reporting APIEPSS 0.7%CVE-2025-59100MEDIUMUnauthenticated Access to the SQLite Database in dormakaba access managerEPSS 0.7%CVE-2026-62835CRITICALAzure Portal Information Disclosure VulnerabilityEPSS 0.7%CVE-2024-30260LOWUndici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipelineEPSS 0.7%CVE-2025-4631CRITICALProfitori 2.0.6.0 - 2.1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation via stocktend_object EndpointEPSS 0.7%CVE-2025-5511MEDIUMquequnlong shiyi-blog photos improper authorizationEPSS 0.7%CVE-2025-49746CRITICALAzure Machine Learning Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2020-9061—Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10EPSS 0.7%CVE-2015-10033LOWjvvlee MerlinsBoard Grade improper authorizationEPSS 0.7%CVE-2022-39340MEDIUMOpenFGA Information DisclosureEPSS 0.7%CVE-2024-21166MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior anEPSS 0.7%CVE-2017-0895—Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note thatEPSS 0.7%CVE-2022-33712—Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in EPSS 0.7%CVE-2024-12782MEDIUMFujifilm Business Innovation Apeos C3070/Apeos C5570/Apeos C6580 Web Interface index.html#hashHome improper authorizationEPSS 0.7%