Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2020-9081LOWThere is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific modEPSS 0.2%CVE-2025-66291MEDIUMOrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Interview AttachmentsEPSS 0.2%CVE-2026-2209MEDIUMWeKan Custom Translation translationBody.js setCreateTranslation improper authorizationEPSS 0.2%CVE-2022-36837MEDIUMIntent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive informatEPSS 0.2%CVE-2021-44204—Local privilege escalation via named pipe due to improper access control checksEPSS 0.2%CVE-2023-28378MEDIUMImproper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potEPSS 0.2%CVE-2026-18175HIGHIBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]EPSS 0.2%CVE-2025-22171MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.EPSS 0.2%CVE-2024-36438HIGHeLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to cEPSS 0.2%CVE-2025-66290MEDIUMOrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Candidate AttachmentsEPSS 0.2%CVE-2026-2294MEDIUMUiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.09 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings UpdateEPSS 0.2%CVE-2026-61082MEDIUMVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.EPSS 0.2%CVE-2023-42973MEDIUMPrivate Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with imprEPSS 0.2%CVE-2022-34434MEDIUMCloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. AEPSS 0.2%CVE-2026-13514LOWChess Play and Learn App com.chess AndroidManifest.xml backupEPSS 0.2%CVE-2025-22239HIGHCVE-2025-22239 salt advisoryEPSS 0.2%CVE-2025-65963MEDIUMCFiles Unauthorized Folder/ZIP Access in Public SpacesEPSS 0.2%CVE-2025-43403MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOSEPSS 0.2%CVE-2023-28385HIGHImproper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially EPSS 0.2%CVE-2026-44362MEDIUMOP-TEE's subkey rollback protection can be bypassed with older subkey versionsEPSS 0.2%