Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-57898CRITICALIn Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to EPSS 0.7%CVE-2025-0211MEDIUMCampcodes School Faculty Scheduling System index.php file inclusionEPSS 0.7%CVE-2025-4602MEDIUMeMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File ReadEPSS 0.7%CVE-2026-46402HIGHMicrosoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directoryEPSS 0.7%CVE-2025-47956MEDIUMWindows Security App Spoofing VulnerabilityEPSS 0.7%CVE-2022-42734HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service usiEPSS 0.7%CVE-2024-5986CRITICALRemote Arbitrary File Write with Arbitrary Data in h2oai/h2o-3EPSS 0.7%CVE-2026-30276CRITICALAn arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via theEPSS 0.7%CVE-2022-42732HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service usiEPSS 0.7%CVE-2024-38173MEDIUMMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-22178MEDIUMA file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.0EPSS 0.7%CVE-2024-21870MEDIUMA file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. AEPSS 0.7%CVE-2022-31739HIGHWhen downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-EPSS 0.7%CVE-2026-5821HIGHImage Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion via Post Meta Field InjectionEPSS 0.7%CVE-2025-66292HIGHDPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interfaceEPSS 0.7%CVE-2026-85684HIGHmarker through 2.0.0 Path Traversal via upload filenameEPSS 0.7%CVE-2024-39904HIGHCode Execution Vulnerability via Local File Path Traversal in VnoteEPSS 0.7%CVE-2026-16139HIGHArbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code executionEPSS 0.7%CVE-2026-41107HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.7%CVE-2026-66324MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.7%