Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-55527HIGHPraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable locationEPSS 0.3%CVE-2025-11973MEDIUM简数采集器 <= 2.6.3 - Authenticated (Admin+) Arbitrary File ReadEPSS 0.3%CVE-2026-41088HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-6205HIGHAn external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-7280EPSS 0.3%CVE-2024-39303MEDIUMWeblate vulnerabler to improper sanitization of project backupsEPSS 0.3%CVE-2026-44641HIGHMicrosoft APM: plugin.json component paths escape plugin root and copy arbitrary host files during installEPSS 0.3%CVE-2026-41412MEDIUMalf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension ScriptEPSS 0.3%CVE-2025-64739MEDIUMZoom Clients - External Control of File Name or PathEPSS 0.3%CVE-2020-36868HIGHNagios XI < 5.7.3 Privilege escalation via Insecure getprofile.sh ScriptEPSS 0.3%CVE-2026-19084HIGHShared Files < 1.7.70 - Unauthenticated Arbitrary File ReadEPSS 0.3%CVE-2026-16926CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2025-62382HIGHFrigate Vulnerable to Arbitrary File Read via Export Thumbnail "image_path" parameterEPSS 0.3%CVE-2026-35032HIGHJellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tunerEPSS 0.3%CVE-2025-10306LOWBackup Bolt <= 1.4.1 - Authenticated (Admin+) Arbitrary File DownloadEPSS 0.3%CVE-2026-42593MEDIUMGotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routesEPSS 0.3%CVE-2020-1984HIGHSecdo: Privilege escalation via hardcoded script pathEPSS 0.3%CVE-2025-0202MEDIUMTCS BaNCS REPORTS_SHOW_FILE.jsp file inclusionEPSS 0.3%CVE-2021-22539HIGHCode execution in VSCode-bazel via malicious Bazel config filesEPSS 0.3%CVE-2026-1669HIGHArbitrary File Read in Keras via HDF5 External DatasetsEPSS 0.3%CVE-2026-62865HIGHTypeBot: Arbitrary server file read via Send Email block attachment pathEPSS 0.3%