Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-10154MEDIUMDolibarr ERP CRM messaging.php authorizationEPSS 0.2%CVE-2025-12505MEDIUMweDocs <= 2.1.14 - Missing Authorization to Settings UpdateEPSS 0.2%CVE-2023-40430MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes witEPSS 0.2%CVE-2026-28881MEDIUMA privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive userEPSS 0.2%CVE-2026-10294MEDIUMPackageKit API pk-transaction.c g_file_test improper authorizationEPSS 0.2%CVE-2020-1690—An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a containerEPSS 0.2%CVE-2026-83805MEDIUMNautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobsEPSS 0.2%CVE-2022-31609HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources fEPSS 0.2%CVE-2025-9294MEDIUMQuiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results DeletionEPSS 0.2%CVE-2024-24900MEDIUMDell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low priEPSS 0.2%CVE-2025-12360MEDIUMBetter Find and Replace <= 1.7.7 - Missing AuthorizationEPSS 0.2%CVE-2026-5283MEDIUMInappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a craEPSS 0.2%CVE-2025-2850MEDIUMGL.iNet GL-A1300 Slate Plus Download Interface improper authorizationEPSS 0.2%CVE-2025-12367MEDIUMSiteSEO – SEO Simplified <= 1.3.1 - Missing Authorization to Authenticated (Author+) Plugin Settings UpdateEPSS 0.2%CVE-2026-10070MEDIUMmacrozheng mall Super Admin Password update improper authorizationEPSS 0.2%CVE-2022-3787HIGHA vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alEPSS 0.2%CVE-2026-23623MEDIUMCollabora Online vulnerable to Authorization BypassEPSS 0.2%CVE-2025-32964MEDIUMManageWiki vulnerable to permission bypass when disabling extensions requiring certain permissions in Special:ManageWiki/extensionsEPSS 0.2%CVE-2021-25399—Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.EPSS 0.2%CVE-2021-25499HIGHIntent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access contEPSS 0.2%