Fallos del tipo CWE-288

673 resultados

Controle de acesso inadequado

A aplicação falha em validar corretamente se um usuário tem permissão para executar uma ação ou acessar um recurso específico. Sem essa validação, um atacante consegue contornar restrições e executar operações que deveria estar proibido (ler dados sensíveis, modificar registros de outros usuários, acessar áreas administrativas, etc.).

Ejemplo

Um sistema bancário permite que qualquer usuário autenticado mude a senha de qualquer outra conta apenas alterando o ID de usuário na requisição, sem verificar se aquele usuário é realmente o dono da conta ou um administrador autorizado.

Cómo mitigar

Implemente verificações de autorização em toda requisição sensível: valide se o usuário logado é realmente quem deveria estar fazendo aquela ação (propriedade, role, permissão explícita). Centralize essa lógica em um componente de controle de acesso reutilizável e teste-a sistematicamente com usuários de diferentes perfis.

CVE-2017-9944A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 8EPSS 3.0%CVE-2022-0992CRITICALSiteGround Security <= 1.2.5 - Authentication Bypass via 2FA SetupEPSS 2.9%CVE-2023-3277CRITICALMStore API <= 4.10.7 - Unauthorized Account Access and Privilege EscalationEPSS 2.9%CVE-2020-15633HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-EPSS 2.8%CVE-2018-4852A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to theEPSS 2.7%CVE-2020-27865HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware versionEPSS 2.6%CVE-2026-24207CRITICALNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of thisEPSS 2.6%CVE-2020-14485OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiateEPSS 2.5%CVE-2019-13526Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker toEPSS 2.4%CVE-2026-28411CRITICALWeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`EPSS 2.3%CVE-2020-6091CRITICALAn exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MEPSS 2.3%CVE-2016-9497Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channelEPSS 2.2%CVE-2019-5165HIGHAn exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A speciallEPSS 2.1%CVE-2025-22462CRITICALAn authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows EPSS 2.1%CVE-2025-27129CRITICALAn authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted EPSS 2.1%CVE-2024-9933CRITICALWatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value CheckEPSS 2.0%CVE-2024-28200CRITICALN-central Authentication BypassEPSS 1.9%CVE-2022-1681HIGHAuthentication Bypass Using an Alternate Path or Channel in requarks/wikiEPSS 1.9%CVE-2025-0364CRITICALBigAntSoft BigAnt Server Account Registration Bypass to File Upload RCEEPSS 1.9%CVE-2023-2834CRITICALBookIt <= 2.3.7 - Authentication BypassEPSS 1.9%