Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-15123LOWJeecgBoot datarule improper authorizationEPSS 0.3%CVE-2026-46552MEDIUMNocoDB: Shared-base link access can invite arbitrary users as persistent base membersEPSS 0.3%CVE-2024-37159LOWEvmos is missing create validator checkEPSS 0.3%CVE-2026-56320HIGHCapgo - Org/App Scope Mismatch in Device Creation EndpointEPSS 0.3%CVE-2026-55217MEDIUMGLPI: Unallowed modfication of knowbase items comments and translationsEPSS 0.3%CVE-2024-40783HIGHThe issue was addressed with improved restriction of data container access. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6,EPSS 0.3%CVE-2025-10731MEDIUMReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure to Data ExportEPSS 0.3%CVE-2026-56295MEDIUMCapgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API KeysEPSS 0.3%CVE-2025-14348MEDIUMweMail <= 2.0.7 - Insufficient Authorization via x-wemail-user Header to Sensitive Information DisclosureEPSS 0.3%CVE-2025-3014HIGHInsecure direct object references (IDOR) in NightWolf Penetration PlatformEPSS 0.3%CVE-2026-97647MEDIUMningzichun student-management-system editLog.php authorizationEPSS 0.3%CVE-2025-3013HIGHInsecure direct object references (IDOR) in NightWolf Penetration PlatformEPSS 0.3%CVE-2024-13692MEDIUMReturn Refund and Exchange For WooCommerce <= 4.4.5 - Authenticated (Subscriber+) Insecure Direct Object ReferenceEPSS 0.3%CVE-2026-82594LOWLogNet grpc-spring-boot-starter Annotation Processing improper authorizationEPSS 0.3%CVE-2026-33146MEDIUMDocmost's Public Share Search Exposes Metadata of Restricted ChildrenEPSS 0.3%CVE-2026-53602MEDIUMnebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid certificateEPSS 0.3%CVE-2025-12777MEDIUMYITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Wishlist Token Disclosure to Wishlist Item DeletionEPSS 0.3%CVE-2026-1597MEDIUMBdtask SalesERP Administrative Endpoint improper authorizationEPSS 0.3%CVE-2026-21584HIGHThis High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of BamEPSS 0.3%CVE-2026-56231HIGHCapgo - Broken Object Level Authorization in Build Job Control via jobId ParameterEPSS 0.3%