Fallos del tipo CWE-288

675 resultados

Controle de acesso inadequado

A aplicação falha em validar corretamente se um usuário tem permissão para executar uma ação ou acessar um recurso específico. Sem essa validação, um atacante consegue contornar restrições e executar operações que deveria estar proibido (ler dados sensíveis, modificar registros de outros usuários, acessar áreas administrativas, etc.).

Ejemplo

Um sistema bancário permite que qualquer usuário autenticado mude a senha de qualquer outra conta apenas alterando o ID de usuário na requisição, sem verificar se aquele usuário é realmente o dono da conta ou um administrador autorizado.

Cómo mitigar

Implemente verificações de autorização em toda requisição sensível: valide se o usuário logado é realmente quem deveria estar fazendo aquela ação (propriedade, role, permissão explícita). Centralize essa lógica em um componente de controle de acesso reutilizável e teste-a sistematicamente com usuários de diferentes perfis.

CVE-2026-18577HIGHIncomplete patch leads to administrative account takeoverEPSS 54.1%KEVCVE-2024-23917CRITICALIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possibleEPSS 53.7%CVE-2026-10523CRITICALAn Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthentEPSS 51.9%CVE-2024-7314CRITICALanji-plus AJ-Report Authentication BypassEPSS 51.7%CVE-2024-33610CRITICAL"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' sessioEPSS 50.0%CVE-2023-2982CRITICALWordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication BypassEPSS 46.2%CVE-2023-2986CRITICALAbandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication BypassEPSS 42.5%CVE-2026-18556HIGHUnauthenticated administrative account takeoverEPSS 40.2%KEVCVE-2017-5174An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerabiliEPSS 40.0%CVE-2022-25369CRITICALAn issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists dEPSS 40.0%CVE-2024-10081CRITICALCodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypasEPSS 39.9%CVE-2024-47010HIGHPath Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.EPSS 37.8%CVE-2025-34143CRITICALETQ Reliance CG Authentication Bypass via Trailing Space RCEEPSS 32.7%CVE-2024-13181HIGHPath Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresseEPSS 32.4%CVE-2023-20269MEDIUMA vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTDEPSS 25.5%KEVCVE-2024-39309CRITICALZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass VulnerabilityEPSS 20.2%CVE-2024-2056CRITICALArtica Proxy Loopback Services Remotely Accessible UnauthenticatedEPSS 16.7%CVE-2026-7567CRITICALTemporary Login <= 1.0.0 - Authentication Bypass to Account TakeoverEPSS 9.2%CVE-2026-34040HIGHMoby: AuthZ plugin bypass with oversized request bodyEPSS 9.1%CVE-2020-27866HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R622EPSS 8.7%