Fallos del tipo CWE-285

1605 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2023-20184MEDIUMCisco DNA Center Software API VulnerabilitiesEPSS 0.5%CVE-2026-55775LOWOpenBao's System Backend allows Unauthorized Management of the containing NamespaceEPSS 0.5%CVE-2022-3683HIGHSDM600 API web services authorization validationEPSS 0.5%CVE-2026-5412CRITICALJuju CloudSpec API could leak senstive informationEPSS 0.5%CVE-2026-18720MEDIUMkalcaddle kodbox msgWarning Plugin action improper authorizationEPSS 0.5%CVE-2026-7109MEDIUMcode-projects Invoice System in Laravel API Endpoint item improper authorizationEPSS 0.5%CVE-2026-8241MEDIUMIndustrial Application Software IAS Canias ERP RMI iasGetServerInfoEvent improper authorizationEPSS 0.5%CVE-2025-48371MEDIUMOpenFGA Authorization BypassEPSS 0.5%CVE-2025-11521HIGHAstra Security Suite – Firewall & Malware Scan <= 0.2 - Unauthenticated Arbitrary File UploadEPSS 0.5%CVE-2024-42490HIGHauthentik has Insufficient Authorization for several API endpointsEPSS 0.5%CVE-2024-21402HIGHMicrosoft Outlook Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-32678MEDIUMZulip vulnerable to insufficient authorization check for edition/deletion of messages and topics in private streams by former subscribersEPSS 0.5%CVE-2026-33950CRITICALsignalk-server: Privilege Escalation by Admin Role Injection via /enableSecurityEPSS 0.5%CVE-2025-13808MEDIUMorionsec orion-ops User Profile UserController.java update improper authorizationEPSS 0.5%CVE-2026-77686MEDIUMDolibarr Account card.php improper authorizationEPSS 0.5%CVE-2026-92087HIGH@fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of composed authEPSS 0.5%CVE-2023-39401CRITICALParameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be reaEPSS 0.5%CVE-2023-39402CRITICALParameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be reaEPSS 0.5%CVE-2023-39400CRITICALParameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be reaEPSS 0.5%CVE-2026-3835MEDIUMPrevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File AccessEPSS 0.5%