Fallos del tipo CWE-285

1607 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-2860MEDIUMfeng_ha_ha/megagao ssm-erp/production_ssm EmployeeController.java improper authorizationEPSS 0.4%CVE-2026-54551MEDIUMWireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' and interfaces' traffic stats to every user (missing per-user authorization)EPSS 0.4%CVE-2025-60784MEDIUMA vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.EPSS 0.4%CVE-2025-14546MEDIUMVersions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the EPSS 0.4%CVE-2023-22938MEDIUMPermissions Validation Failure in the ‘sendemail’ REST API Endpoint in Splunk EnterpriseEPSS 0.4%CVE-2025-10374MEDIUMShenzhen Sixun Business Management System OperatorStop improper authorizationEPSS 0.4%CVE-2024-58367HIGHSurrealDB before 2.0.4 Improper Authorization via SELECT PermissionsEPSS 0.4%CVE-2025-63691CRITICALIn pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interfaEPSS 0.4%CVE-2026-28839MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app mayEPSS 0.4%CVE-2026-20286MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2026-75792MEDIUMIBM Sterling Secure Proxy is vulnerable to multiple issuesEPSS 0.4%CVE-2025-27399MEDIUMMastodon's domain blocks & rationales ignore user approval when visibility set as "users"EPSS 0.4%CVE-2026-20285MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2024-38370MEDIUMGLPI allows API document download without rightsEPSS 0.4%CVE-2025-6713HIGHMongoDB Server may be susceptible to privilege escalation due to $mergeCursors stageEPSS 0.4%CVE-2025-54585HIGHGitProxy is vulnerable to a new branch approval exploitEPSS 0.4%CVE-2025-20264MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2023-33020HIGHImproper Authorization in WLAN HostEPSS 0.4%CVE-2026-1193MEDIUMMineAdmin View view improper authorizationEPSS 0.4%CVE-2023-28584HIGHImproper Authorization in WLAN HostEPSS 0.4%