Fallos del tipo CWE-285

1605 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2024-42036LOWAccess permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.1%CVE-2023-28973HIGHJunos OS Evolved: The 'sysmanctl' shell command allows a local user to gain access to some administrative actions EPSS 0.1%CVE-2026-3671MEDIUMFreedom Factory dGEN1 org.ethereumphone.walletmanager.testing123 TokenBalanceContentProvider improper authorizationEPSS 0.1%CVE-2026-84621MEDIUMAn authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, maEPSS 0.1%CVE-2026-84615MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, EPSS 0.1%CVE-2026-17433MEDIUMnanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorizationEPSS 0.1%CVE-2023-21461MEDIUMImproper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turEPSS 0.1%CVE-2026-3674MEDIUMFreedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppProvider improper authorizationEPSS 0.1%CVE-2026-3669MEDIUMFreedom Factory dGEN1 com.dgen.alarm AlarmService improper authorizationEPSS 0.1%CVE-2026-3670MEDIUMFreedom Factory dGEN1 com.dgen.alarm improper authorizationEPSS 0.1%CVE-2026-3667MEDIUMFreedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppService improper authorizationEPSS 0.1%CVE-2026-3675MEDIUMFreedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppReceiver improper authorizationEPSS 0.1%CVE-2022-36857LOWImproper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application EPSS 0.1%CVE-2026-28845MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access pEPSS 0.1%CVE-2022-45874MEDIUMHuawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain filEPSS 0.1%CVE-2023-41819MEDIUM A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unEPSS 0.1%CVE-2026-84556MEDIUMAn authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.1%CVE-2026-65353MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An aEPSS 0.1%CVE-2026-84636MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watcEPSS 0.1%CVE-2026-43695MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOEPSS 0.1%