Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-44362MEDIUMOP-TEE's subkey rollback protection can be bypassed with older subkey versionsEPSS 0.2%CVE-2026-18367CRITICALA privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2EPSS 0.2%CVE-2022-36870MEDIUMPending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global aEPSS 0.2%CVE-2023-21440MEDIUMImproper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.EPSS 0.2%CVE-2025-22169MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2025-22175MEDIUMJira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of senEPSS 0.2%CVE-2022-36872MEDIUMPending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackEPSS 0.2%CVE-2022-36871MEDIUMPending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackeEPSS 0.2%CVE-2025-10736MEDIUMReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data ManipulationEPSS 0.2%CVE-2025-2528LOWImproper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use EPSS 0.2%CVE-2025-53709MEDIUMAccess control issues impacting secure-upload serviceEPSS 0.2%CVE-2025-46296MEDIUMAn authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access adminiEPSS 0.2%CVE-2026-46620MEDIUMe107: CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check()EPSS 0.2%CVE-2023-2782MEDIUMSensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) befoEPSS 0.2%CVE-2023-26466HIGHA user with non-Admin access can change a configuration file on the client to modify the Server URL.EPSS 0.2%CVE-2023-25517HIGH NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources fEPSS 0.2%CVE-2022-4062HIGHA CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gEPSS 0.2%CVE-2023-22636MEDIUMAn unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allowEPSS 0.2%CVE-2023-35022LOWIBM InfoSphere Information Server improper authenticationEPSS 0.2%CVE-2025-67603MEDIUMLack of client authorization allows arbitrary users to influence the firewall configurationEPSS 0.2%