Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-84799MEDIUMCraft CMS before 5.11.0 PII Disclosure via GraphQL User RelationsEPSS 0.3%CVE-2025-11729MEDIUMPPWP: Password Protect Pages, Posts & Full or Partial Content <= 1.9.15 - Improper Authorization To Authenticated (Contributor+) Master Password ExposureEPSS 0.3%CVE-2026-39347MEDIUMOrangeHRM's Self‑Appraisal Submission of Admin Users Can Be Modified After CompletionEPSS 0.3%CVE-2024-1803MEDIUMEmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient Authorization Checks to Block UsualEPSS 0.3%CVE-2025-6525MEDIUM70mai 1S Configuration Config.cgi improper authorizationEPSS 0.3%CVE-2026-63752MEDIUMSurrealDB before 3.1.0 RELATE Statement Record OverwriteEPSS 0.3%CVE-2025-12720MEDIUMg-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product DeletionEPSS 0.3%CVE-2026-32692HIGHUnauthorized update of out-of-scope Vault secretsEPSS 0.3%CVE-2026-2079MEDIUMyeqifu warehouse Menu Management MenuController.java deleteMenu improper authorizationEPSS 0.3%CVE-2026-2078MEDIUMyeqifu warehouse Permission Management PermissionController.java deletePermission improper authorizationEPSS 0.3%CVE-2026-97324MEDIUMYunaiV/zhijiantianya ruoyi-vue-pro Demo-order Payment Callback PayDemoOrderController.java updateDemoOrderPaid improper authorizationEPSS 0.3%CVE-2026-96556MEDIUMNeethuharii CafeManagement AddCashierCode.php addcashier improper authorizationEPSS 0.3%CVE-2026-2076MEDIUMyeqifu warehouse User Management Endpoint UserController.java deleteUser improper authorizationEPSS 0.3%CVE-2026-2077MEDIUMyeqifu warehouse Role Management RoleController.java deleteRole improper authorizationEPSS 0.3%CVE-2025-15119LOWJeecgBoot list queryPageList improper authorizationEPSS 0.3%CVE-2026-10269MEDIUMdecolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorizationEPSS 0.3%CVE-2025-11227MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns DisclosureEPSS 0.3%CVE-2026-34738MEDIUMAVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request ParameterEPSS 0.3%CVE-2025-59305HIGHImproper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migratioEPSS 0.3%CVE-2024-21987MEDIUMImproper Authorization Vulnerability in SnapCenterEPSS 0.3%