Fallos del tipo CWE-610

96 resultados

Controle de acesso inadequado

A aplicação falha em validar corretamente se um usuário tem permissão para acessar um recurso, funcionalidade ou dado específico. Isso permite que atacantes contornem restrições e acessem informações confidenciais, modifiquem dados ou executem ações que não deveriam estar autorizadas a fazer.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado, mas não valida se ele é dono da conta antes de exibir o extrato. Um atacante muda o ID da conta na URL (de ?conta=123 para ?conta=456) e consegue ver extratos alheios.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível: valide que o usuário não apenas está autenticado, mas que possui permissão específica para aquele recurso. Use modelos de controle de acesso bem definidos (RBAC, ABAC) e revise sistematicamente os pontos críticos onde recursos são expostos.

CVE-2023-4089LOWWAGO: Multiple products vulnerable to local file inclusionEPSS 0.5%CVE-2025-9065HIGHRockwell Automation ThinManager® Server-Side Request Forgery VulnerabilityEPSS 0.5%CVE-2026-19032MEDIUMjackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.PathEPSS 0.5%CVE-2023-38046MEDIUMPAN-OS: Read System Files and Resources During Configuration CommitEPSS 0.5%CVE-2026-78966MEDIUMExternally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a EPSS 0.5%CVE-2022-23439MEDIUMA externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafteEPSS 0.4%CVE-2026-79256HIGHExternally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromisEPSS 0.4%CVE-2026-55389HIGHdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`EPSS 0.4%CVE-2025-5877MEDIUMFengoffice Feng Office Document Upload ApplicationDataObject.class.php xml external entity referenceEPSS 0.4%CVE-2025-2875HIGHCWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality wheEPSS 0.4%CVE-2025-11035MEDIUMJinher OA text xml external entity referenceEPSS 0.4%CVE-2026-32008HIGHOpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation GuardEPSS 0.4%CVE-2026-12788MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity referenceEPSS 0.4%CVE-2024-6717HIGHNomad Vulnerable to Allocation Directory Path Escape Through Archive UnpackingEPSS 0.4%CVE-2025-1225MEDIUMywoa WXCallBack Interface XMLParse.java extract xml external entity referenceEPSS 0.4%CVE-2024-28962MEDIUMDell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulneraEPSS 0.4%CVE-2024-42168HIGHHCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerabilityEPSS 0.4%CVE-2023-22616HIGHAn issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driEPSS 0.4%CVE-2026-62960HIGHGit for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on WindowsEPSS 0.4%CVE-2026-55390HIGHArbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gateEPSS 0.4%