Fallos del tipo CWE-288

675 resultados

Controle de acesso inadequado

A aplicação falha em validar corretamente se um usuário tem permissão para executar uma ação ou acessar um recurso específico. Sem essa validação, um atacante consegue contornar restrições e executar operações que deveria estar proibido (ler dados sensíveis, modificar registros de outros usuários, acessar áreas administrativas, etc.).

Ejemplo

Um sistema bancário permite que qualquer usuário autenticado mude a senha de qualquer outra conta apenas alterando o ID de usuário na requisição, sem verificar se aquele usuário é realmente o dono da conta ou um administrador autorizado.

Cómo mitigar

Implemente verificações de autorização em toda requisição sensível: valide se o usuário logado é realmente quem deveria estar fazendo aquela ação (propriedade, role, permissão explícita). Centralize essa lógica em um componente de controle de acesso reutilizável e teste-a sistematicamente com usuários de diferentes perfis.

CVE-2021-33700HIGHSAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the vEPSS 0.2%CVE-2024-31463MEDIUMIronic-image allows unauthenticated local access to Ironic APIEPSS 0.2%CVE-2025-55012HIGHZed AI Agent Remote Code ExecutionEPSS 0.2%CVE-2025-13013MEDIUMMitigation bypass in the DOM: Core & HTML componentEPSS 0.2%CVE-2026-1917MEDIUMLogin Disable - Less critical - Access bypass - SA-CONTRIB-2026-008EPSS 0.2%CVE-2025-46286MEDIUMA logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent pEPSS 0.2%CVE-2026-88260HIGHAuthentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in BrainzcoEPSS 0.2%CVE-2026-35642MEDIUMOpenClaw < 2026.3.25 - Authorization Bypass in Group Reactions via requireMention BypassEPSS 0.2%CVE-2025-12760MEDIUMEmail TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-115EPSS 0.2%CVE-2024-42178LOWHCL MyXalytics is affected by a failure to restrict URL access vulnerabilityEPSS 0.2%CVE-2022-42275HIGHNVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a losEPSS 0.2%CVE-2025-24332HIGHAuthenticated admin user can connect baseband internally from one board to another without needing to re-authenticationEPSS 0.2%CVE-2024-7125HIGHAuthentication Bypass Vulnerability in Hitachi Ops Center Common ServicesEPSS 0.2%CVE-2025-43422MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a dEPSS 0.2%CVE-2024-35214HIGHVulnerability in CylanceOPTICS Windows Installer Package Impacts CylanceOPTICS for WindowsEPSS 0.2%CVE-2026-32031MEDIUMOpenClaw < 2026.2.26 - Authentication Bypass via Path Canonicalization Mismatch in /api/channels GatewayEPSS 0.2%CVE-2024-25036MEDIUMIBM Cognos Controller authentication bypassEPSS 0.2%CVE-2026-36175MEDIUMAn issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access viaEPSS 0.2%CVE-2025-68708LOWSailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock iEPSS 0.2%CVE-2022-40725HIGHPingID Desktop PIN attempt lockout bypass.EPSS 0.2%