Fallos del tipo CWE-425

123 resultados

Falta de validação de autorização em URLs, scripts ou arquivos restritos

A aplicação web não verifica adequadamente se o usuário tem permissão para acessar determinadas URLs, scripts ou arquivos antes de conceder o acesso. Um atacante consegue burlar os controles de autorização e acessar recursos que deveriam estar protegidos, como páginas administrativas, arquivos de configuração ou funcionalidades restritas.

Ejemplo

Um sistema bancário permite acesso à página de transferências via URL direta (/admin/transferir) apenas verificando se o usuário está logado, mas não confere se ele é administrador. Um usuário comum descobre a URL e transfere dinheiro sem autorização.

Cómo mitigar

Implemente verificação de autorização explícita em cada endpoint ou recurso restrito, não apenas autenticação. Use um padrão como controle de acesso baseado em papéis (RBAC) ou atributos (ABAC), centralizando a lógica de permissões e testando-a sistematicamente para todas as rotas sensíveis.

CVE-2026-34056HIGHOpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only DataEPSS 0.3%CVE-2025-55736CRITICALflaskBlog allows arbitrary privilege escalationEPSS 0.3%CVE-2025-59797MEDIUMProfession Fit 5.0.99 Build 44910 allows authorization bypass via a direct request for /api/challenges/{id} and also URLs for eversports, thEPSS 0.3%CVE-2026-9610LOWMultiple Vulnerabilities in IBM DatacapEPSS 0.3%CVE-2026-33217HIGHNATS allows MQTT clients to bypass ACL checksEPSS 0.3%CVE-2025-10287LOWroncoo roncoo-pay orderQuery direct requestEPSS 0.2%CVE-2024-23573LOWHCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects theEPSS 0.2%CVE-2026-7500MEDIUMOrg.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabledEPSS 0.2%CVE-2026-60011MEDIUMSharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the EPSS 0.2%CVE-2025-57823LOWA direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, EPSS 0.2%CVE-2025-41404MEDIUMDirect request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-publicEPSS 0.2%CVE-2025-53073MEDIUMIn Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as aEPSS 0.2%CVE-2026-34051MEDIUMOpenEMR has Improper ACL On Import/Export PopupEPSS 0.2%CVE-2026-8205MEDIUMConcrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendarEPSS 0.2%CVE-2026-21760MEDIUMUnauthorized Access to Admin Functionality via Forced BrowsingEPSS 0.2%CVE-2025-62778LOWFrappe Learning allowed students to access the Quiz Form via direct URLEPSS 0.2%CVE-2026-14953MEDIUMFrauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to improper enforcement of role-based access controlEPSS 0.2%CVE-2025-65011HIGHUnauthorized Access to files in WODESYS WD-R608U routerEPSS 0.2%CVE-2026-32867MEDIUMOPEXUS eComplaint unauthenticated file uploadEPSS 0.2%CVE-2025-15587HIGHCredentials exposure in tinycontrol devicesEPSS 0.2%