Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-50152CRITICALCeph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only usersEPSS 0.2%CVE-2023-3899HIGHSubscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configurationEPSS 0.2%CVE-2026-24890HIGHOpenEMR Portal Users Can Forge Provider SignaturesEPSS 0.2%CVE-2025-8147MEDIUMLWSCache <= 2.8.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation via lwscache_activatePlugin FunctionEPSS 0.2%CVE-2022-34363MEDIUMDell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisphere for VMAX applicEPSS 0.2%CVE-2024-13724MEDIUMWallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing AuthorizationEPSS 0.2%CVE-2025-7221MEDIUMGiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation UpdateEPSS 0.2%CVE-2025-62520MEDIUMMantisBT unauthorized disclosure of private project column configurationEPSS 0.2%CVE-2026-61837MEDIUMRabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authenticated AMQP user without resource/management permission checksEPSS 0.2%CVE-2024-57954MEDIUMPermission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service cEPSS 0.2%CVE-2026-70923MEDIUMVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.2%CVE-2026-62444MEDIUMVulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%CVE-2025-2397MEDIUMChina Mobile P22g-CIac Telnet Service improper authorizationEPSS 0.2%CVE-2022-30730MEDIUMImproper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.EPSS 0.2%CVE-2026-60152MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that aEPSS 0.2%CVE-2025-65020MEDIUMRallly Has Unauthorized Poll Duplication via Insecure Direct Object Reference (IDOR)EPSS 0.2%CVE-2025-12958LOWRankology SEO and Analytics Tool <= 2.0 - Incorrect Authorization to Authenticated (Editor+) Header & Footer Code CreationEPSS 0.2%CVE-2024-40814HIGHA downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An EPSS 0.2%CVE-2025-10902MEDIUMOriginality.ai AI Checker <= 1.0.15 - Missing Authorization to Authenticated (Subscriber+) Scan Log Deletion via ' ai_scan_result_remove'EPSS 0.2%CVE-2024-50617HIGHVulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorizEPSS 0.2%