Fallos del tipo CWE-285

1589 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-53795CRITICALMicrosoft PC Manager Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-20393HIGHCisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Privilege Escalation VulnerabilityEPSS 0.6%CVE-2026-15622MEDIUMpoco-ai poco-claw Workspace API workspace.py get_workspace_file authorizationEPSS 0.6%CVE-2022-4804HIGHImproper Authorization in usememos/memosEPSS 0.6%CVE-2024-29033HIGHGoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspaceEPSS 0.6%CVE-2023-20186HIGHA vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allEPSS 0.6%CVE-2024-8509HIGHMigration toolkit for virtualization: forklift-controller: empty bearer token may perform authenticationEPSS 0.6%CVE-2024-38371HIGHInsufficient access control for OAuth2 Device Code flow in authentikEPSS 0.6%CVE-2025-53106HIGHGraylog vulnerable to privilege escalation through API tokensEPSS 0.6%CVE-2026-70200CRITICALAzure Logic Apps Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2026-56160CRITICALAzure Red Hat OpenShift (ARO) Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2025-0928HIGHArbitrary executable upload via authenticated endpointEPSS 0.6%CVE-2021-23136MEDIUMImproper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command CeEPSS 0.6%CVE-2022-32169MEDIUMbytebase - Improper AuthorizationEPSS 0.6%CVE-2022-32170MEDIUMbytebase - Improper AuthorizationEPSS 0.6%CVE-2024-52287MEDIUMauthentik performs insufficient validation of OAuth scopesEPSS 0.6%CVE-2026-28312CRITICALSolarWinds Serv-U Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-20381HIGHCisco Network Services Orchestrator Configuration Update Authorization Bypass VulnerabilityEPSS 0.6%CVE-2026-66422HIGHApache Tomcat: Servlet role references can bypass declarative role constraintsEPSS 0.6%CVE-2024-52528CRITICALAuth Token can be passed dummy or wrong the middleware response is 200 OKEPSS 0.6%