Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-72742CRITICALDSPy 3.3.0b1 Local File Read via Image/Audio Output Field ParsingEPSS 0.4%CVE-2025-59483HIGHBIG-IP Configuration utility and tmsh vulnerabilityEPSS 0.4%CVE-2026-47214HIGHDocling: Unsafe URI and Path Handling in HTML BackendEPSS 0.4%CVE-2026-78208HIGHexceljs through 4.4.0 Path Traversal via Unvalidated addImage filenameEPSS 0.4%CVE-2026-45556CRITICALRoxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`EPSS 0.4%CVE-2026-79653MEDIUMIn Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enaEPSS 0.4%CVE-2026-35076HIGHArbitrary file delete vulnerability in method bac-scanresultEPSS 0.4%CVE-2024-12036HIGHCS Framework <= 7.1 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.4%CVE-2026-35080HIGHArbitrary file delete vulnerability in method ugw-restoreinfoEPSS 0.4%CVE-2026-35078HIGHArbitrary file delete vulnerability in method ugw-logstopEPSS 0.4%CVE-2026-35079HIGHArbitrary file delete vulnerability in method ugw-restoreEPSS 0.4%CVE-2026-35077HIGHArbitrary file delete vulnerability in method ugw-delete-fileEPSS 0.4%CVE-2024-6937MEDIUMformtools.org Form Tools Import Option List edit.php curl_exec file inclusionEPSS 0.4%CVE-2026-60009HIGHIn Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled EPSS 0.4%CVE-2026-62385HIGHNLTK 3.9.4 Path Traversal via FrameNet and NKJP ReadersEPSS 0.4%CVE-2023-21566HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-76210HIGHphpMyFAQ before v4.1.6 Local File Disclosure via PDF ExportEPSS 0.4%CVE-2026-84478MEDIUMWWBN AVideo Unauthenticated Arbitrary Log File DeletionEPSS 0.4%CVE-2026-30282CRITICALAn arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internalEPSS 0.4%CVE-2024-21545HIGHProxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against maliEPSS 0.4%