Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-50148CRITICALMetabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File WriteEPSS 0.4%CVE-2025-27147HIGHGLPI Inventory plugin has Improper Access Control VulnerabilityEPSS 0.4%CVE-2024-9142CRITICALLocal File Inclusion (LFI) in Olgu Computer Systems' e-BelediyeEPSS 0.4%CVE-2026-53940HIGHConda: Entry-point path traversal in noarch:python install (arbitrary file write) — canonical Python implementationEPSS 0.4%CVE-2025-0630MEDIUMWestern Telematic Inc NPS Series, DSM Series, CPM Series External Control of File Name or PathEPSS 0.4%CVE-2025-25761HIGHHkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.EPSS 0.4%CVE-2025-20269MEDIUMCisco Evolved Programmable Network Manager and Prime Infrastructure Arbitrary File Download VulnerabilityEPSS 0.4%CVE-2026-76553MEDIUMWP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path TraversalEPSS 0.4%CVE-2026-72842CRITICALOpenWrt luci-app-lxc ACL Inconsistency Authentication BypassEPSS 0.4%CVE-2025-36506MEDIUMExternal control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a speEPSS 0.4%CVE-2025-26684MEDIUMMicrosoft Defender Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-15540MEDIUMSourceCodester Online Book Store System Administrative index.php php file inclusionEPSS 0.4%CVE-2026-44019HIGHDocling Core has insufficient validation of image reference URIsEPSS 0.4%CVE-2026-55700HIGHpnpm: stage download writes outside destination via manifest version traversalEPSS 0.4%CVE-2026-19011MEDIUMTinyAGI agents.ts buildSystemPrompt file inclusionEPSS 0.4%CVE-2026-18127HIGHExternal control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full wrEPSS 0.4%CVE-2023-47147MEDIUMIBM Secure Proxy file manipulationEPSS 0.4%CVE-2025-12654LOWMigration, Backup, Staging – WPvivid Backup & Migration <= 0.9.120 - Authenticated (Admin+) Arbitrary Directory CreationEPSS 0.4%CVE-2026-76158CRITICALDatiphy Data Management Center - External Control of File Name or PathEPSS 0.4%CVE-2026-23529HIGHArbitrary File Read in Google BigQuery Sink connectorEPSS 0.4%