Fallos del tipo CWE-285

1592 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-10707MEDIUMJeecgBoot sendMsg improper authorizationEPSS 0.4%CVE-2025-10989MEDIUMyangzongzhuan RuoYi selectAll improper authorizationEPSS 0.4%CVE-2016-7035HIGHAn authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileEPSS 0.4%CVE-2025-8547MEDIUMatjiu pybbs Email Verification improper authorizationEPSS 0.4%CVE-2023-28325MEDIUMAn improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the EPSS 0.4%CVE-2026-32807HIGHdataCycle Public DataLink Text File Download Ignores Validity And AuthorizationEPSS 0.4%CVE-2026-32806HIGHdataCycle Authorization Bypass Via /remote_renderEPSS 0.4%CVE-2026-90521MEDIUMjaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorizationEPSS 0.4%CVE-2026-19979MEDIUMGL.iNet XE3000 WebDAV Service MOVE authorizationEPSS 0.4%CVE-2026-34656MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2026-19997MEDIUMWebkul Bagisto Backend Sales RMA Endpoint requests authorizationEPSS 0.4%CVE-2023-32709MEDIUMLow-privileged User can View Hashed Default Splunk PasswordEPSS 0.4%CVE-2020-27779—A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker tEPSS 0.4%CVE-2025-11030MEDIUMTutorials-Website Employee Management System HTTP Request all-applied-leave.php improper authorizationEPSS 0.4%CVE-2021-25417—Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.EPSS 0.4%CVE-2025-10977LOWJeecgBoot deleteBatch improper authorizationEPSS 0.4%CVE-2025-15126LOWJeecgBoot getPositionUserList improper authorizationEPSS 0.4%CVE-2026-32716HIGHSciTokens: Authorization Bypass via Incorrect Scope Path Prefix CheckingEPSS 0.4%CVE-2024-41670HIGHPayPal Official Module for PrestaShop has Improperly Implemented Security Check for StandardEPSS 0.4%CVE-2024-1289MEDIUMLearnPress <= 4.2.6.3 - Insecure Direct Object ReferenceEPSS 0.4%