Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-40086MEDIUMRembg has a Path Traversal via Custom Model LoadingEPSS 0.6%CVE-2022-42891HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service usiEPSS 0.6%CVE-2022-42893HIGHA vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service usiEPSS 0.6%CVE-2026-9559CRITICALA path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign importsEPSS 0.6%CVE-2026-17431MEDIUMPDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_forEPSS 0.6%CVE-2026-10816HIGHArbitrary File Read (Unauthenticated)EPSS 0.6%CVE-2026-59683CRITICALOpenRGB: local and remote system compromise via arbitrary file write using attacker controlled stringsEPSS 0.6%CVE-2026-90817CRITICALAn unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in whicEPSS 0.6%CVE-2026-59819LOWLiteLLM: Local file read via request-supplied OIDC file referencesEPSS 0.6%CVE-2026-48162CRITICALWazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh managerEPSS 0.6%CVE-2026-84374HIGHLaravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathEPSS 0.6%CVE-2025-65473CRITICALAn arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with AdministraEPSS 0.6%CVE-2024-57394HIGHThe quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to EPSS 0.6%CVE-2026-90946HIGHDeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocketEPSS 0.6%CVE-2024-1603HIGHconfirmedEPSS 0.6%CVE-2025-10134CRITICALGoza - Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File DeletionEPSS 0.6%CVE-2026-35174CRITICALChyrp Lite has a Path Traversal to Remote Code ExecutionEPSS 0.6%CVE-2025-5393CRITICALAlone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary File DeletionEPSS 0.6%CVE-2026-40370HIGHSQL Server Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-33117CRITICALIBM QRadar SIEM command executionEPSS 0.6%