Fallos del tipo CWE-285

1589 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-85878CRITICALAzure Database for PostgreSQL Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-3918CRITICALJob Listings 0.1 - 0.1.1 - Unauthenticated Privilege Escalation via register_action FunctionEPSS 0.5%CVE-2024-11306MEDIUMAltenergy Power Control Software database improper authorizationEPSS 0.5%CVE-2022-39862MEDIUMImproper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorEPSS 0.5%CVE-2025-0484MEDIUMFanli2012 native-php-cms Backend sysconfig_doedit.php improper authorizationEPSS 0.5%CVE-2023-0914MEDIUMImproper Authorization in pixelfed/pixelfedEPSS 0.5%CVE-2022-31670HIGHHarbor fails to validate the user permissions when updating tag retention policiesEPSS 0.5%CVE-2022-32838MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security UpdatEPSS 0.5%CVE-2023-5808HIGHSystem Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products are susceptible to unintended information disclosure via unprivileged access to HNAS configuration backup and diagnostic data.EPSS 0.5%CVE-2023-0583MEDIUMVK Blocks <= 1.57.0.5 - Authenticated(Contributor+) Settings UpdateEPSS 0.5%CVE-2022-0027MEDIUMCortex XSOAR: Incorrect Authorization Vulnerability When Generating ReportsEPSS 0.5%CVE-2023-3574MEDIUMImproper Authorization in pimcore/customer-data-frameworkEPSS 0.5%CVE-2023-30948MEDIUMRetrieval of Attachments to Comments lacks AuthorizationEPSS 0.5%CVE-2025-43585HIGHAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.5%CVE-2021-42000MEDIUMPing Identity PingFederate Password Reset and Password Change Mishandling with an authentication policy in parallel reset flowsEPSS 0.5%CVE-2022-31671HIGHHarbor fails to validate the user permissions when reading and updating job execution logs through the P2P preheat execution logsEPSS 0.5%CVE-2024-9082MEDIUMSourceCodester Online Eyewear Shop User Creation Users.php improper authorizationEPSS 0.5%CVE-2020-9049HIGHvictor Web Client and C•CURE Web Client JSON Web Token (JWT) VulnerabilityEPSS 0.5%CVE-2024-47084MEDIUMCORS origin validation is not performed when the request has a cookie in GradioEPSS 0.5%CVE-2024-45044HIGHBareos's negative command ACLs can be circumvented by abbreviating commandsEPSS 0.5%