Fallos del tipo CWE-285

1608 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-9835MEDIUMmacrozheng mall cancelUserOrder cancelOrder authorizationEPSS 0.3%CVE-2026-42202MEDIUMnova-toggle-5: Improper authorization on toggle endpoint allowed non-Nova users to modify boolean fieldsEPSS 0.3%CVE-2025-58386CRITICALIn Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorizatioEPSS 0.3%CVE-2024-56335HIGHPrivilege escalation allows organization groups to be updated/deleted if their UUID is known in vaultwardenEPSS 0.3%CVE-2024-3027MEDIUMSmart Slider 3 <= 3.5.1.22 - Missing Authorization to Limited File UploadEPSS 0.3%CVE-2026-9410MEDIUMSushmi-pal Invoice-System Profile Workflow profile improper authorizationEPSS 0.3%CVE-2026-9409MEDIUMSushmi-pal Invoice-System User Management user improper authorizationEPSS 0.3%CVE-2025-29778MEDIUMKyverno ignores subjectRegExp and IssuerRegExpEPSS 0.3%CVE-2026-4548MEDIUMmickasmt next-saas-stripe-starter update-user-role.ts updateUserrole improper authorizationEPSS 0.3%CVE-2026-84036HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.3%CVE-2026-45345MEDIUMOpen WebUI: Missing authorization check at the model update function - models from other users can be updatedEPSS 0.3%CVE-2023-28055HIGH Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the saEPSS 0.3%CVE-2025-8839MEDIUMjshERP Endpoint addUser improper authorizationEPSS 0.3%CVE-2026-13511LOWVoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorizationEPSS 0.3%CVE-2025-3550MEDIUMwowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System detail improper authorizationEPSS 0.3%CVE-2023-0665MEDIUMVault PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer MetadataEPSS 0.3%CVE-2026-43792MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be ablEPSS 0.3%CVE-2025-3567MEDIUMveal98 小牛肉 Echo 开源社区系统 Ticket LoginTicketInterceptor.java preHandle improper authorizationEPSS 0.3%CVE-2025-8401MEDIUMHT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information ExposureEPSS 0.3%CVE-2025-65033HIGHRallly Broken Authorization: Any User Can Pause or Resume Any Poll via Poll ID ManipulationEPSS 0.3%