Fallos del tipo CWE-639

2497 resultados

Falsificação de referência direta a objeto (IDOR)

A aplicação não valida se o usuário tem permissão para acessar um recurso identificado por um parâmetro (como ID de usuário, pedido ou documento). Um atacante modifica esse parâmetro na URL ou requisição para acessar dados de outros usuários. É uma falha de autorização que confunde autenticação (saber quem você é) com controle de acesso (o que você pode ver).

Ejemplo

Um banco permite consultar extrato via URL /extrato?conta_id=12345. Um cliente autenticado muda conta_id para 12346 e acessa o extrato de outro cliente. A aplicação validou apenas se o usuário estava logado, não se tinha direito àquele extrato específico.

Cómo mitigar

Em cada requisição, verifique explicitamente se o usuário autenticado tem permissão para acessar aquele recurso específico (compare o ID solicitado com o contexto do usuário logado). Use IDs opacos/indiretos gerados pelo servidor em vez de sequências previsíveis, sempre como camada adicional, nunca como única proteção.

CVE-2026-1704MEDIUMAppointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information ExposureEPSS 0.2%CVE-2026-100878MEDIUMzhistaredu StarTraining authRole Endpoint SysUser.java SysUser.isAdmin authorizationEPSS 0.2%CVE-2026-10212MEDIUMAstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorizationEPSS 0.2%CVE-2025-56254MEDIUMPHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An aEPSS 0.2%CVE-2026-81654LOWNextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings UpdateEPSS 0.2%CVE-2026-81651LOWNextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOREPSS 0.2%CVE-2025-64282MEDIUMWordPress Radius Blocks plugin <= 2.2.1 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.2%CVE-2026-15058LOWImproper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to dEPSS 0.2%CVE-2016-20033HIGHWowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exeEPSS 0.2%CVE-2026-11369HIGHIDOR in Comment API Allows Cross-Process Comment Read and WriteEPSS 0.2%CVE-2026-9248LOWAuthorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to cEPSS 0.2%CVE-2025-65097HIGHInsecure Direct Object Reference (IDOR) Allows Unauthorized Deletion of User CollectionsEPSS 0.2%CVE-2024-47495HIGHJunos OS Evolved: In a dual-RE scenario a locally authenticated attacker with shell privileges can take over the device.EPSS 0.2%CVE-2026-100618HIGHCapgo App Icon Update Privilege Escalation via Service-Role WorkerEPSS 0.2%CVE-2026-52841LOWEasy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google syncEPSS 0.2%CVE-2025-12954LOWTimetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOREPSS 0.2%CVE-2026-10780MEDIUMStatic Block <= 2.2 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode 'id' AttributeEPSS 0.2%CVE-2024-41254MEDIUMAn issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowinEPSS 0.2%CVE-2026-14212MEDIUMAmelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOREPSS 0.2%CVE-2026-78581MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in KibanaEPSS 0.2%