Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2024-21545HIGHProxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against maliEPSS 0.4%CVE-2025-55316HIGHAzure Connected Machine Agent Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-19913HIGHCVE-2026-19913EPSS 0.4%CVE-2026-76217HIGHGitPython before 3.1.58 Arbitrary File Read via pathspec-from-fileEPSS 0.4%CVE-2026-43891HIGHchangedetection.io: Arbitrary Local File Read via crafted backup restoreEPSS 0.4%CVE-2024-12861MEDIUMW2S – Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.4%CVE-2026-22783CRITICALIris Allows Arbitrary File Deletion via Mass Assignment in Datastore File ManagementEPSS 0.4%CVE-2026-23835MEDIUMLobeHub Vulnerable to Improper Authorization in Presigned UploadEPSS 0.4%CVE-2026-31939HIGHPath Traversal (Arbitrary File Delete) in Chamilo LMSEPSS 0.4%CVE-2025-58769LOWauth0-PHP: Improper File Type Handling in Bulk User ImportEPSS 0.4%CVE-2026-83603HIGHNetdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCEEPSS 0.3%CVE-2026-40893HIGHGotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and MoveEPSS 0.3%CVE-2020-37080HIGHwebTareas 2.0.p8 - Arbitrary File DeletionEPSS 0.3%CVE-2026-91797HIGHFoxit PDF Editor/Reader Portfolio Directory Traversal Remote Code Execution VulnerabilityEPSS 0.3%CVE-2020-37078HIGHi-doit Open Source CMDB 1.14.1 - Arbitrary File DeletionEPSS 0.3%CVE-2020-36878HIGHReQuest Serious Play F3 Media Player <= 3.0.0 Directory Traversal File DisclosureEPSS 0.3%CVE-2025-0124MEDIUMPAN-OS: Authenticated File Deletion Vulnerability on the Management Web InterfaceEPSS 0.3%CVE-2024-1244CRITICALRemote code execution and local privilege escalation due to UNC access and NetNTLMv2 hash theftEPSS 0.3%CVE-2026-77693HIGHOrder Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajaxEPSS 0.3%CVE-2026-85176HIGHDbGate through 7.2.6 Arbitrary File Read and Write via file:// jslidEPSS 0.3%