Fallos del tipo CWE-288

675 resultados

Controle de acesso inadequado

A aplicação falha em validar corretamente se um usuário tem permissão para executar uma ação ou acessar um recurso específico. Sem essa validação, um atacante consegue contornar restrições e executar operações que deveria estar proibido (ler dados sensíveis, modificar registros de outros usuários, acessar áreas administrativas, etc.).

Ejemplo

Um sistema bancário permite que qualquer usuário autenticado mude a senha de qualquer outra conta apenas alterando o ID de usuário na requisição, sem verificar se aquele usuário é realmente o dono da conta ou um administrador autorizado.

Cómo mitigar

Implemente verificações de autorização em toda requisição sensível: valide se o usuário logado é realmente quem deveria estar fazendo aquela ação (propriedade, role, permissão explícita). Centralize essa lógica em um componente de controle de acesso reutilizável e teste-a sistematicamente com usuários de diferentes perfis.

CVE-2022-23720HIGHPingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties fileEPSS 0.2%CVE-2026-0602MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2025-40743HIGHA vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINEPSS 0.2%CVE-2026-84777HIGHWordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerabilityEPSS 0.2%CVE-2026-81796HIGHWordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-82225HIGHWordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-42745HIGHWordPress Smart Online Order for Clover plugin <= 1.6.0 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-50194HIGHSteeltoe vulnerable to management-port isolation bypass via spoofed Host headerEPSS 0.2%CVE-2025-40761HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (AllEPSS 0.2%CVE-2026-18636MEDIUMVelociraptor VFSGetBuffer API path deny list bypassEPSS 0.2%CVE-2026-12703HIGHBypass of 2FA for Connections via Unattended Access in TeamViewer for macOSEPSS 0.2%CVE-2020-11005MEDIUMInternal NCryptDecrypt method could be used externally from WindowsHello library.EPSS 0.2%CVE-2022-22189HIGHContrail Service Orchestration: An authenticated local user may have their permissions elevated via the device via management interface without authenticationEPSS 0.2%CVE-2026-81783HIGHWordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulnerabilityEPSS 0.2%CVE-2026-47200MEDIUMNuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`EPSS 0.2%CVE-2026-3035MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2026-1747MEDIUMAuthentication Bypass Using an Alternate Path or Channel in GitLabEPSS 0.2%CVE-2025-13986MEDIUMDisable Login Page - Critical - Access bypass - SA-CONTRIB-2025-124EPSS 0.2%CVE-2025-3652MEDIUMPetlibro Smart Pet Feeder Platform through 1.7.31 Audio Information Disclosure via API endpointEPSS 0.2%CVE-2026-35654MEDIUMOpenClaw < 2026.3.25 - Authorization Bypass in Microsoft Teams Feedback InvokeEPSS 0.2%