Fallos del tipo CWE-285

1605 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-49278MEDIUMRocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor ImpersonationEPSS 0.4%CVE-2025-5182MEDIUMSummer Pearl Group Vacation Rental Management Platform Listing authorizationEPSS 0.4%CVE-2026-73644CRITICALOpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grantEPSS 0.4%CVE-2026-95805MEDIUMMISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restrictionEPSS 0.4%CVE-2026-64743MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPaEPSS 0.4%CVE-2026-2109MEDIUMjsbroks COCO Annotator Delete Category undo improper authorizationEPSS 0.4%CVE-2026-35407MEDIUMSaleor has Cross-Account Email Change via Unbound Confirmation TokenEPSS 0.4%CVE-2024-39418MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2024-13821MEDIUMWP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking ManipulationEPSS 0.4%CVE-2025-2600MEDIUMImproper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEPSS 0.4%CVE-2026-19838MEDIUMWebkul Bagisto Backend Reporting Endpoint sales authorizationEPSS 0.4%CVE-2026-19836MEDIUMWebkul Bagisto Backend Customer Detail Feature view authorizationEPSS 0.4%CVE-2022-31669MEDIUMHarbor fails to validate the user permissions when updating tag immutability policiesEPSS 0.4%CVE-2026-44715HIGHOpenMRS has Broken Access Control in HL7 ConfigurationEPSS 0.4%CVE-2026-30847CRITICALWekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session TokensEPSS 0.4%CVE-2026-84076HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.4%CVE-2026-47663HIGHPathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and cross-resource mutationEPSS 0.4%CVE-2026-6584MEDIUMTransformerOptimus SuperAGI User Update Endpoint user.py update_user authorizationEPSS 0.4%CVE-2026-6585MEDIUMTransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorizationEPSS 0.4%CVE-2025-2639MEDIUMJIZHICMS Article release.html improper authorizationEPSS 0.4%