Fallos del tipo CWE-285

1588 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-33105CRITICALMicrosoft Azure Kubernetes Service Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-33823CRITICALMicrosoft Team Events Portal Information Disclosure VulnerabilityEPSS 0.7%CVE-2020-26183MEDIUMDell EMC NetWorker versions prior to 19.3.0.2 contain an improper authorization vulnerability. Certain remote users with low privileges may EPSS 0.7%CVE-2024-24830CRITICALOpenObserve Privilege Escalation Vulnerability in Users APIEPSS 0.7%CVE-2019-10159MEDIUMcfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration EPSS 0.7%CVE-2024-36467HIGHAuthentication privilege escalation via user groups due to missing authorization checksEPSS 0.7%CVE-2020-36729MEDIUMSlideshow, Image Slider by 2J <= 1.3.31 - Authorization BypassEPSS 0.7%CVE-2024-43460HIGHDynamics 365 Business Central Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2021-21096MEDIUMAdobe Bridge Genuine Software Service Incorrect Permission Assignment could lead to Denial-of-ServiceEPSS 0.7%CVE-2026-25893CRITICALFUXA Unauthenticated Remote Code Execution via Admin JWT MintingEPSS 0.7%CVE-2025-3536MEDIUMTutorials-Website Employee Management System delete-user.php improper authorizationEPSS 0.7%CVE-2023-40683HIGHIBM OpenPages with Watson privilege escalationEPSS 0.7%CVE-2023-48309MEDIUMnext-auth vulnerable to possible user mocking that bypasses basic authenticationEPSS 0.7%CVE-2025-2320MEDIUM274056675 springboot-openai-chatgpt User submit improper authorizationEPSS 0.7%CVE-2025-3537MEDIUMTutorials-Website Employee Management System update-user.php improper authorizationEPSS 0.7%CVE-2023-38220HIGHFull page cache enumeration via cookie X-Magento-VaryEPSS 0.7%CVE-2024-21179MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior anEPSS 0.7%CVE-2024-25108CRITICALInsufficient authorization allowing elevated access to resources in pixelfedEPSS 0.7%CVE-2023-53895CRITICALPimpMyLog 1.7.14 Improper Access Control via Account Creation EndpointEPSS 0.7%CVE-2022-26310HIGHImproper Authorization in User Management to Vertical Privilege EscalationEPSS 0.7%