Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-39378MEDIUMnbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image EmbeddingEPSS 0.3%CVE-2026-28442HIGHZimaOS: Arbitrary Deletion of Internal System Files via API Path ManipulationEPSS 0.3%CVE-2026-40605MEDIUMTautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APIEPSS 0.3%CVE-2026-10694MEDIUMSourceCodester Online Food Ordering System index.php include file inclusionEPSS 0.3%CVE-2019-25472HIGHIntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFileEPSS 0.3%CVE-2026-77005CRITICALCode Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path TraversalEPSS 0.3%CVE-2026-94401HIGHMISP Arbitrary Local File Read and SSRF via MISP Export UploadEPSS 0.3%CVE-2025-48067MEDIUMOctoPrint vulnerable to possible file extraction via upload endpointsEPSS 0.3%CVE-2026-79426HIGHAn arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to dEPSS 0.3%CVE-2026-29611HIGHOpenClaw < 2026.2.14 - Local File Inclusion via mediaPath Parameter in BlueBubbles Media HandlingEPSS 0.3%CVE-2026-85687HIGHsurya 0.22.1 Unauthenticated Arbitrary File Read via screenshot serverEPSS 0.3%CVE-2026-41693HIGHi18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwriteEPSS 0.3%CVE-2026-77139MEDIUMPath Traversal in extension "Mask" (mask)EPSS 0.3%CVE-2026-5210MEDIUMSourceCodester Leave Application System file inclusionEPSS 0.3%CVE-2026-46399CRITICALAuthenticated Remote Code Execution via File OverwriteEPSS 0.3%CVE-2026-73619HIGHGitPython before 3.1.57 Arbitrary File Read via Repo.archive()EPSS 0.3%CVE-2026-46397MEDIUMhaxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0EPSS 0.3%CVE-2025-8048MEDIUMExternal Control of File path vulnerability has been discovered on Openext Flipper.EPSS 0.3%CVE-2026-48920HIGHJenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inlinEPSS 0.3%CVE-2025-8050MEDIUMExternal Control of File vulnerability has been discovered in opentext Flipper.EPSS 0.3%