Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-25573HIGHA vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-pEPSS 0.4%CVE-2025-62611HIGHaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL serverEPSS 0.4%CVE-2026-19009MEDIUMTinyAGI Message API Endpoint response.ts collectFiles file inclusionEPSS 0.4%CVE-2025-12656LOWMigration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory DeletionEPSS 0.4%CVE-2026-26359HIGHDell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker wEPSS 0.4%CVE-2025-48783HIGHSoar Cloud HRD Human Resource Management System - External Control of File Name or PathEPSS 0.4%CVE-2026-33949HIGH@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary filesEPSS 0.4%CVE-2026-8118MEDIUMRoyal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File SourceEPSS 0.4%CVE-2025-6237CRITICALPath Traversal and Arbitrary File Deletion in invoke-ai/invokeaiEPSS 0.4%CVE-2025-66254HIGHUnauthenticated Arbitrary File Deletion (upgrade_contents.php)EPSS 0.4%CVE-2025-66257CRITICALUnauthenticated Arbitrary File Deletion (patch_contents.php)EPSS 0.4%CVE-2026-24708HIGHAn issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a rooEPSS 0.4%CVE-2022-4983MEDIUMTEC-IT TBarCode SDK 11.15 Remote File CreateEPSS 0.4%CVE-2026-48798HIGHSSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP FilenamesEPSS 0.4%CVE-2011-10030HIGHFoxit PDF Reader < 4.3.1.0218 JavaScript File WriteEPSS 0.4%CVE-2026-9587HIGHAuthenticated Local File Inclusion (LFI) in Switchvox SMB Web PortalEPSS 0.4%CVE-2020-36772MEDIUMCloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to reEPSS 0.4%CVE-2026-15736HIGHMultiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemyEPSS 0.4%CVE-2025-29930MEDIUMimFAQ allows local file inclusion in seo.phpEPSS 0.4%CVE-2025-59511HIGHWindows WLAN Service Elevation of Privilege VulnerabilityEPSS 0.4%