Fallos del tipo CWE-73

671 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-79692HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control EPSS 0.3%CVE-2026-12513MEDIUMShared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path TraversalEPSS 0.3%CVE-2025-49588HIGHLinkwarden Local File Inclusion VulnerabilityEPSS 0.3%CVE-2026-53956MEDIUMRattler vulnerable to package cache path traversal via conda package build stringEPSS 0.3%CVE-2024-12267MEDIUMDrag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File DeletionEPSS 0.3%CVE-2026-24287HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-34967MEDIUMAdminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File WriteEPSS 0.3%CVE-2024-31492HIGHAn external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installEPSS 0.3%CVE-2026-17014MEDIUMWP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzipsEPSS 0.3%CVE-2026-54134HIGHOctoPrint: File exfiltration possible via query parameters on upload endpointsEPSS 0.3%CVE-2026-61647HIGH@roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended vault directoryEPSS 0.3%CVE-2025-29866HIGH: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free EPSS 0.3%CVE-2026-62865HIGHTypeBot: Arbitrary server file read via Send Email block attachment pathEPSS 0.3%CVE-2025-11973MEDIUM简数采集器 <= 2.6.3 - Authenticated (Admin+) Arbitrary File ReadEPSS 0.3%CVE-2024-39303MEDIUMWeblate vulnerabler to improper sanitization of project backupsEPSS 0.3%CVE-2026-42424MEDIUMOpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA PathsEPSS 0.3%CVE-2020-36868HIGHNagios XI < 5.7.3 Privilege escalation via Insecure getprofile.sh ScriptEPSS 0.3%CVE-2025-64739MEDIUMZoom Clients - External Control of File Name or PathEPSS 0.3%CVE-2026-19084HIGHShared Files < 1.7.70 - Unauthenticated Arbitrary File ReadEPSS 0.3%CVE-2026-30240CRITICALBudibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment SecretsEPSS 0.3%