Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-61604CRITICALixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypassEPSS 0.3%CVE-2026-21641HIGHHackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of ReEPSS 0.3%CVE-2023-5948HIGHImproper Authorization in teamamaze/amazefileutilitiesEPSS 0.3%CVE-2024-20414MEDIUMA vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conEPSS 0.3%CVE-2023-28318MEDIUMA vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeleteEPSS 0.3%CVE-2026-21724MEDIUMMissing Protected-field Authorization in Provisioning Contact Points APIEPSS 0.3%CVE-2025-11080MEDIUMzhuimengshaonian wisdom-education ExamInfoController.java selectStudentExamInfoList improper authorizationEPSS 0.3%CVE-2025-65782MEDIUMAn issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update EPSS 0.3%CVE-2024-6347MEDIUMUnauthorized access to ECU functionalityEPSS 0.3%CVE-2025-12304MEDIUMdulaiduwang003 TIME-SEA-PLUS Order Status PayController.java alipayIsSucceed improper authorizationEPSS 0.3%CVE-2025-15118MEDIUMmacrozheng mall Member Endpoint update improper authorizationEPSS 0.3%CVE-2026-11519MEDIUMSourceCodester Inventory System Account Creation users_handler.php improper authorizationEPSS 0.3%CVE-2025-12814MEDIUMSiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings ResetEPSS 0.3%CVE-2026-67332MEDIUM@better-auth/oauth-provider before 1.7.0-beta.4 Authorization BypassEPSS 0.3%CVE-2026-10215MEDIUMDolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorizationEPSS 0.3%CVE-2025-68481MEDIUMFastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSOEPSS 0.3%CVE-2026-70665MEDIUMDoorkeeper OpenID Connect: DCR endpoint persists unvalidated client-supplied scopesEPSS 0.3%CVE-2022-30722MEDIUMImplicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of SEPSS 0.3%CVE-2026-42876MEDIUMExternal Secrets Operator: Priviledge escalation with secret overwritingEPSS 0.3%CVE-2025-11510MEDIUMFileBird <= 6.4.9 - Improper Authorization to Authenticated (Author+) Settings ResetEPSS 0.3%