Fallos del tipo CWE-285

1588 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-7778CRITICALIcons Factory <= 1.6.12 - Missing Authorization to Unauthenticated Arbitrary File Deletion via delete_files() FunctionEPSS 0.7%CVE-2026-47298HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2021-4334HIGHFancy Product Designer <= 4.6.9 - Insufficient Authorization to Arbitrary Options Update via fpd_update_optionsEPSS 0.7%CVE-2025-26683HIGHAzure Playwright Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2024-27916HIGH`GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any authenticated userEPSS 0.7%CVE-2021-27772HIGHHCL Sametime is vulnerable to an information disclosureEPSS 0.7%CVE-2022-0406MEDIUMImproper Authorization in janeczku/calibre-webEPSS 0.7%CVE-2023-38508MEDIUMTuleap allows preview of a linked artifact with a type does not respect permissionsEPSS 0.7%CVE-2024-34463MEDIUMBPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lackEPSS 0.7%CVE-2025-59271HIGHRedis Enterprise Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2025-61524HIGHAn issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.EPSS 0.7%CVE-2025-27509CRITICALSAML authentication vulnerability due to improper SAML response validationEPSS 0.7%CVE-2014-2349—Emerson DeltaV Use of Improper AuthorizationEPSS 0.7%CVE-2024-1043MEDIUMAMP for WP <= 1.0.93.1 - Authenticated(Contributor+) Arbitrary Post Deletion via amppb_remove_saved_layout_dataEPSS 0.7%CVE-2020-10686MEDIUMA flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. EPSS 0.7%CVE-2022-39329LOWProfile of disabled user stays accessibleEPSS 0.7%CVE-2023-42453LOWImproper validation of receipts allows forged read receipts in matrix synapseEPSS 0.7%CVE-2026-57983HIGHMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2023-34460MEDIUMTauri vulnerable to Regression on Filesystem Scope Checks for DotfilesEPSS 0.6%CVE-2024-33749CRITICALDedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.EPSS 0.6%