Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-59682HIGHArbitrary file overwrite and deletion local and remote in OpenRGBEPSS 0.5%CVE-2024-2155MEDIUMSourceCodester Best POS Management System index.php file inclusionEPSS 0.5%CVE-2026-17184CRITICALIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2025-49138MEDIUMHAX CMS vulnerable to Local File Inclusion via saveOutline API Location ParameterEPSS 0.5%CVE-2026-56452HIGHApache MINA SSHD: Path traversal in SCP file receptionEPSS 0.5%CVE-2026-27211CRITICALCloud Hypervisor: Host File Exfiltration via QCOW Backing File AbuseEPSS 0.5%CVE-2026-25628HIGHQdrant affected by arbitrary file write via `/logger` endpointEPSS 0.5%CVE-2026-61462CRITICALmcp-gitlab Path Traversal via job_id ParameterEPSS 0.5%CVE-2025-68155HIGH@vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on DevelopmentEPSS 0.5%CVE-2026-50162MEDIUMoras-go: file store write outside workingDir via symlink traversalEPSS 0.5%CVE-2026-69805HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-20114MEDIUMA vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attackEPSS 0.5%CVE-2025-58158HIGHHarness Affected by Arbitrary File Write in Gitness LFS serverEPSS 0.5%CVE-2026-65802HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-46336HIGHManyfold: Authenticated Path Traversal via File RenameEPSS 0.5%CVE-2026-5809HIGHwpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' ParameterEPSS 0.5%CVE-2024-10672LOWMultiple Page Generator Plugin – MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File DeletionEPSS 0.5%CVE-2026-56705CRITICALAdminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN InjectionEPSS 0.5%CVE-2026-73171HIGHNozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKEPSS 0.5%CVE-2025-64714MEDIUMPrivateBin's template-switching feature allows arbitrary local file inclusion through path traversalEPSS 0.5%