Fallos del tipo CWE-285

1608 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-65033HIGHRallly Broken Authorization: Any User Can Pause or Resume Any Poll via Poll ID ManipulationEPSS 0.3%CVE-2025-65029HIGHRallly Has an IDOR Vulnerability in Participant Deletion Endpoint Allows Unauthorized Removal of Poll ParticipantsEPSS 0.3%CVE-2026-39901MEDIUMmonetr: Protected Transactions Deletable via PUTEPSS 0.3%CVE-2023-32967MEDIUMQTS, QuTScloudEPSS 0.3%CVE-2026-4818MEDIUMSome management operations on data streams are not properly restricted when user does not have the necessary privilegesEPSS 0.3%CVE-2024-21031MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.3%CVE-2024-21018MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.3%CVE-2024-21039MEDIUMVulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versioEPSS 0.3%CVE-2022-46312—The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpEPSS 0.3%CVE-2025-13115MEDIUMmacrozheng mall-swarm/mall Order Details detail improper authorizationEPSS 0.3%CVE-2025-57438MEDIUMThe 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible EPSS 0.3%CVE-2025-15120LOWJeecgBoot getDeptRoleList improper authorizationEPSS 0.3%CVE-2026-13534LOWCherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorizationEPSS 0.3%CVE-2026-41572MEDIUMNote Mark: Unauthenticated read of notes and assets in soft-deleted public booksEPSS 0.3%CVE-2026-17531LOWunitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorizationEPSS 0.3%CVE-2025-15213MEDIUMcode-projects Student File Management System File Download download.php improper authorizationEPSS 0.3%CVE-2026-54012HIGHOpen WebUI: Forged model meta.knowledge allows cross-user file read and deletionEPSS 0.3%CVE-2026-21587HIGHThis High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This ImEPSS 0.3%CVE-2025-30373MEDIUMGraylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong valueEPSS 0.3%CVE-2025-10319MEDIUMJeecgBoot Tenant Log Export exportLog improper authorizationEPSS 0.3%