Fallos del tipo CWE-285

1607 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-7782MEDIUMCodeCanyon Perfex CRM Tenant Clients.php project authorizationEPSS 0.4%CVE-2026-48089HIGHDevGuard has improper authorization on public assetsEPSS 0.4%CVE-2026-56311MEDIUMCapgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPCEPSS 0.4%CVE-2026-31836HIGHMass Assignment Privilege Escalation in CheckmateEPSS 0.4%CVE-2026-50279HIGHCraft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gapEPSS 0.4%CVE-2025-13807MEDIUMorionsec orion-ops API MachineKeyController.java MachineKeyController improper authorizationEPSS 0.4%CVE-2025-15106MEDIUMgetmaxun Authentication Endpoint auth.ts router.get improper authorizationEPSS 0.4%CVE-2026-47740HIGHShopper: Authorization bypass in multiple Livewire admin componentsEPSS 0.4%CVE-2026-34056HIGHOpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only DataEPSS 0.4%CVE-2026-56249HIGHCapgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /channel Name CollisionEPSS 0.4%CVE-2026-60844HIGHVulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Supported versions thaEPSS 0.4%CVE-2023-32717MEDIUMRole-based Access Control (RBAC) Bypass on '/services/indexing/preview' REST Endpoint Can Overwrite Search ResultsEPSS 0.4%CVE-2025-15582MEDIUMdetronetdip E-commerce Product Management Update authorizationEPSS 0.4%CVE-2024-21026MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.4%CVE-2024-21035MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.4%CVE-2023-22931MEDIUM‘createrss’ External Search Command Overwrites Existing RSS Feeds in Splunk EnterpriseEPSS 0.4%CVE-2025-4136MEDIUMWeitong Mall Sale Endpoint improper authorizationEPSS 0.4%CVE-2026-43983HIGHPocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictionsEPSS 0.4%CVE-2025-3924MEDIUMPeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Unauthenticated Email EnumerationEPSS 0.4%CVE-2026-2860MEDIUMfeng_ha_ha/megagao ssm-erp/production_ssm EmployeeController.java improper authorizationEPSS 0.4%