Fallos del tipo CWE-73

669 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2025-8050MEDIUMExternal Control of File vulnerability has been discovered in opentext Flipper.EPSS 0.3%CVE-2026-32204HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-14059MEDIUMEmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path TraversalEPSS 0.3%CVE-2025-0898MEDIUMXpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVGEPSS 0.3%CVE-2026-86995MEDIUMn8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository ReadEPSS 0.3%CVE-2022-34669HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modiEPSS 0.3%CVE-2025-54780HIGHglpi-screenshot-plugin exposes local files in /ajax/screenshot.phpEPSS 0.3%CVE-2026-42597MEDIUMGotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// schemeEPSS 0.3%CVE-2026-26228LOWVLC for Android < 3.7.0 Remote Access Path TraversalEPSS 0.3%CVE-2023-45588HIGHAn external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installEPSS 0.3%CVE-2026-53580HIGHTrilium arbitrary file read and denial of service via file:// URLs in the automatic image-download featureEPSS 0.3%CVE-2026-16054CRITICALDrag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce OracleEPSS 0.3%CVE-2026-12513MEDIUMShared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path TraversalEPSS 0.3%CVE-2025-4674HIGHUnexpected command execution in untrusted VCS repositories in cmd/goEPSS 0.3%CVE-2025-61879HIGHIn Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.EPSS 0.3%CVE-2026-54584MEDIUMmport trusts environment-controlled temporary directories in privileged metadata extractionEPSS 0.3%CVE-2026-45725HIGHcompliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path TraversalEPSS 0.3%CVE-2026-30240CRITICALBudibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment SecretsEPSS 0.3%CVE-2026-34492HIGHAirwall - Arbitrary file readEPSS 0.3%CVE-2026-3602MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injectionEPSS 0.3%