Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-61873HIGHGrav before 9.1.8 Arbitrary File Write via Twig-Processed FilenameEPSS 0.5%CVE-2025-43951CRITICALLabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via theEPSS 0.5%CVE-2024-51961HIGHLocal file inclusion (LFI) vulnerability in ArcGIS ServerEPSS 0.5%CVE-2025-9920MEDIUMCampcodes Recruitment Management System index.php include file inclusionEPSS 0.5%CVE-2026-50462HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-11451HIGHAuto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.3 - Unauthenticated Arbitrary File ReadEPSS 0.5%CVE-2026-20358CRITICALCisco Crosswork Security Hardening Release: August 2026EPSS 0.5%CVE-2026-90932HIGHLaraDashboard 0.9.2 through 1.2.2 Path Traversal RCEEPSS 0.5%CVE-2025-2409HIGHAdmin Authorized System File corruptionEPSS 0.5%CVE-2026-23898HIGHJoomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdateEPSS 0.5%CVE-2025-54162MEDIUMFile Station 5EPSS 0.5%CVE-2026-53915HIGHIn JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configurationEPSS 0.5%CVE-2026-55699MEDIUMpnpm: reserved bin name deletes PNPM_HOME during global removeEPSS 0.4%CVE-2026-58192HIGHAppium: Unauthenticated arbitrary file/directory deletion in @appium/storage-pluginEPSS 0.4%CVE-2026-85668HIGHXinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-registerEPSS 0.4%CVE-2024-33860MEDIUMAn issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File SEPSS 0.4%CVE-2025-48781HIGHSoar Cloud HRD Human Resource Management System - External Control of File Name or PathEPSS 0.4%CVE-2024-9275MEDIUMjeanmarc77 123solar admin_invt2.php file inclusionEPSS 0.4%CVE-2026-26202HIGHPenpot has Arbitrary File Read via create-font-variant RPC endpointEPSS 0.4%CVE-2025-59291HIGHConfidential Azure Container Instances Elevation of Privilege VulnerabilityEPSS 0.4%