Fallos del tipo CWE-285

1592 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-1847MEDIUMzj1983 zz improper authorizationEPSS 0.5%CVE-2023-1910MEDIUMGetwid – Gutenberg Blocks <= 1.8.3 - Improper Authorization via get_remote_templates REST endpointEPSS 0.5%CVE-2022-36454MEDIUMA vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profileEPSS 0.5%CVE-2025-4017MEDIUM20120630 Novel-Plus LogController.java list improper authorizationEPSS 0.5%CVE-2026-49877HIGHApache ActiveMQ: Authenticated web users retain admin access by default in the Web ConsoleEPSS 0.5%CVE-2026-45187MEDIUMApache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System JobsEPSS 0.5%CVE-2025-1007MEDIUMImproper Authorization in /user/namespace/{namespace}/detailsEPSS 0.5%CVE-2026-16126MEDIUMzevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorizationEPSS 0.5%CVE-2023-2345MEDIUMSourceCodester Service Provider Management System improper authorizationEPSS 0.5%CVE-2026-13549MEDIUMCodeAstro Complaint Management System Report Endpoint Report.php deletereport authorizationEPSS 0.5%CVE-2025-3587MEDIUMZeroWdd/code-projects studentmanager getTeacherList improper authorizationEPSS 0.5%CVE-2023-36611MEDIUM The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with EPSS 0.5%CVE-2017-16726—Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been deEPSS 0.5%CVE-2026-3817MEDIUMSourceCodester Patients Waiting Area Queue Management System patient-search.php improper authorizationEPSS 0.5%CVE-2024-6000HIGHFooEvents for WooCommerce <= 1.19.20 - Improper Authorization to (Contributor+) Arbitrary File UploadEPSS 0.5%CVE-2024-23649HIGHAny authenticated user may obtain private message details from other users on the same instanceEPSS 0.5%CVE-2024-55954HIGHOpenObserve Improper Authorization Allows Admin User to Remove Root UserEPSS 0.5%CVE-2024-28285CRITICALA Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reEPSS 0.5%CVE-2024-0870MEDIUMYITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings UpdateEPSS 0.5%CVE-2026-20190HIGHCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.5%