Fallos del tipo CWE-285

1588 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-5246MEDIUMCesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorizationEPSS 0.6%CVE-2025-1607MEDIUMSourceCodester Best Employee Management System salary_slip.php authorizationEPSS 0.6%CVE-2021-33723—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profileEPSS 0.6%CVE-2025-21275HIGHWindows App Package Installer Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-12347MEDIUMGuangzhou Huayi Intelligent Technology Jeewms Druid Monitoring Interface index.html improper authorizationEPSS 0.6%CVE-2026-55077HIGHCoder: User-admin role can reset owner account passwordEPSS 0.6%CVE-2022-36453HIGHA vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their pEPSS 0.6%CVE-2024-12901MEDIUMFoxCMS API Endpoint Site.php improper authorizationEPSS 0.6%CVE-2022-2901HIGHImproper Authorization in chatwoot/chatwootEPSS 0.6%CVE-2024-2441HIGHVikBooking < 1.6.8 - Insecure Direct Object ReferencesEPSS 0.6%CVE-2019-25149HIGHGallery Images Ape <= 2.0.6 - Authenticated Plugin DeactivationEPSS 0.6%CVE-2022-27583CRITICALA remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affectedEPSS 0.6%CVE-2025-2114MEDIUMShenzhen Sixun Software Sixun Shanghui Group Business Management System Reset Password Interface OperatorStop.asp improper authorizationEPSS 0.6%CVE-2022-39356HIGHDiscourse user account takeover via email and invite linkEPSS 0.6%CVE-2024-37282HIGHIt was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsEPSS 0.6%CVE-2017-9268MEDIUMopen-build-service retrigger / wipebinaries hitting the wrong project bypassing access permissionsEPSS 0.6%CVE-2022-47409CRITICALAn issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 tEPSS 0.6%CVE-2024-13694HIGHWooCommerce Wishlist <= 1.8.7 - Unauthenticated Wishlist Disclosure via download_pdf_file FunctionEPSS 0.6%CVE-2024-7851MEDIUMSourceCodester Yoga Class Registration System Add User Users.php improper authorizationEPSS 0.6%CVE-2023-22348MEDIUMReading host_configs does not honour contact groupsEPSS 0.6%