Fallos del tipo CWE-346

590 resultados

Validação incorreta de origem (Origin Validation Error)

A aplicação falha em validar corretamente a origem (origem HTTP, domínio, referência) de requisições ou recursos, permitindo que um atacante simule estar vindo de uma origem confiável. Isso quebra mecanismos de segurança como CORS, CSRF e validações de referência, abrindo porta para ataques cross-site.

Ejemplo

Um banco implementa proteção CSRF verificando se o header `Origin` é igual a `banco.com.br`, mas não valida subdomínios. Um atacante consegue fazer requisições de `falso.banco.com.br` que passam na validação e transferem dinheiro da vítima.

Cómo mitigar

Valide a origem de forma rigorosa usando whitelist explícita (não apenas prefixos ou sufixos), implemente tokens CSRF anti-previsíveis, configure CORS corretamente evitando `Access-Control-Allow-Origin: *`, e use SameSite cookies quando possível.

CVE-2021-26737MEDIUMPrivilege Escalation Using PID Reuse in ZCC macOSEPSS 0.1%CVE-2026-2457MEDIUMWebSocket Message Spoofing via Permalink Embed ManipulationEPSS 0.1%CVE-2026-9989MEDIUMInappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a EPSS 0.1%CVE-2023-25188MEDIUMAn issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardeniEPSS 0.1%CVE-2026-74968MEDIUMSite isolation issue in the Graphics: WebRender componentEPSS 0.1%CVE-2026-72702CRITICALGrav CMS before 2.0.16 Origin Validation Bypass via RefererEPSS 0.1%CVE-2026-59297LOWSpring Cloud Function can incorrectly determine if URI is secureEPSS 0.1%CVE-2026-41886HIGHlocize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext EditorEPSS 0.1%CVE-2024-31127HIGHMacOS Zscaler Client Connector Local Privilege EscalationEPSS 0.1%CVE-2026-34720LOWZammad has an origin validation error in SSO mechanismEPSS 0.1%CVE-2026-94111MEDIUMTencent BrowserSkill through 0.3.0 Origin Validation Error in Local WebSocket DaemonEPSS 0.1%CVE-2025-67825MEDIUMAn issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verifiedEPSS 0.1%CVE-2026-53656MEDIUMFiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server dataEPSS 0.1%CVE-2025-8074MEDIUMOrigin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary EPSS 0.1%CVE-2026-17984LOWInappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin datEPSS 0.1%CVE-2025-1787MEDIUMLocal admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows usEPSS 0.1%CVE-2026-7439MEDIUMAgentFlow Local Web API Content-Type Validation BypassEPSS 0.1%CVE-2024-5905LOWCortex XDR Agent: Local Windows User Can Disrupt Functionality of the AgentEPSS 0.1%CVE-2025-66593MEDIUMAn origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricteEPSS 0.1%CVE-2026-6102HIGHMSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation VulnerabilityEPSS 0.1%