Fallos del tipo CWE-639

2495 resultados

Falsificação de referência direta a objeto (IDOR)

A aplicação não valida se o usuário tem permissão para acessar um recurso identificado por um parâmetro (como ID de usuário, pedido ou documento). Um atacante modifica esse parâmetro na URL ou requisição para acessar dados de outros usuários. É uma falha de autorização que confunde autenticação (saber quem você é) com controle de acesso (o que você pode ver).

Ejemplo

Um banco permite consultar extrato via URL /extrato?conta_id=12345. Um cliente autenticado muda conta_id para 12346 e acessa o extrato de outro cliente. A aplicação validou apenas se o usuário estava logado, não se tinha direito àquele extrato específico.

Cómo mitigar

Em cada requisição, verifique explicitamente se o usuário autenticado tem permissão para acessar aquele recurso específico (compare o ID solicitado com o contexto do usuário logado). Use IDs opacos/indiretos gerados pelo servidor em vez de sequências previsíveis, sempre como camada adicional, nunca como única proteção.

CVE-2026-18439MEDIUMTutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' ParameterEPSS 0.3%CVE-2026-1206MEDIUMElementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor TemplateEPSS 0.3%CVE-2026-76907MEDIUMLaSuite Doc: Public Documents EnumerationEPSS 0.3%CVE-2026-58580MEDIUMLobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource WritesEPSS 0.3%CVE-2026-56823MEDIUMAutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping TriggeringEPSS 0.3%CVE-2022-48505—This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to modify protected partEPSS 0.3%CVE-2026-63745MEDIUMSurrealDB before 3.1.0 Authorization Bypass via Composite Record-idEPSS 0.2%CVE-2025-43732MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3EPSS 0.2%CVE-2025-14882LOWInsecure direct object referenceEPSS 0.2%CVE-2025-14881LOWInsecure direct object referenceEPSS 0.2%CVE-2026-3473MEDIUMImproper file ownership validation in the Boards API allows unauthorised file accessEPSS 0.2%CVE-2025-13452MEDIUMAdmin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated User Impersonation in Order MessagesEPSS 0.2%CVE-2026-18423LOWConcrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs allowing an authenticated user with permission on one Express entity to delete or rename saved search presEPSS 0.2%CVE-2025-41069MEDIUMInsecure Direct Object References (IDOR) in DeporSite of T-Innova DeporSiteEPSS 0.2%CVE-2025-49352MEDIUMWordPress Order Cancellation & Returns for WooCommerce plugin <= 1.1.10 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-25574MEDIUMPayload Affected by Cross-Collection IDOR in payload-preferences Access Control (Multi-Auth Environments)EPSS 0.2%CVE-2025-65670MEDIUMAn Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulatingEPSS 0.2%CVE-2025-65020MEDIUMRallly Has Unauthorized Poll Duplication via Insecure Direct Object Reference (IDOR)EPSS 0.2%CVE-2026-10597MEDIUMITPison|OMICARD EDM - Insecure Direct Object ReferenceEPSS 0.2%CVE-2026-84025LOWBEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOREPSS 0.2%