Fallos del tipo CWE-73

671 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-92164MEDIUMStreamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local filesEPSS 0.3%CVE-2026-3602MEDIUMIBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injectionEPSS 0.3%CVE-2026-16444HIGHImproper Validation of File Paths in TeamViewer Desktop ClientsEPSS 0.3%CVE-2025-2982MEDIUMLegrand SMS PowerView file inclusionEPSS 0.3%CVE-2024-6714HIGHAn issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.EPSS 0.3%CVE-2025-62842HIGHHBS 3 Hybrid Backup SyncEPSS 0.3%CVE-2023-5247HIGHMalicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software EPSS 0.3%CVE-2025-36398MEDIUMDS8900F and DS8A00 Information DisclosureEPSS 0.3%CVE-2026-78679HIGHGitPython before 3.1.59 Arbitrary File Read via TagReference.createEPSS 0.3%CVE-2026-2351MEDIUMTask Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.3%CVE-2021-3626HIGHWindows version of Multipass unauthenticated localhost tcp control socket can perform mountsEPSS 0.2%CVE-2026-77006CRITICALWebTotem Backups < 1.1.0 - Subscriber+ Arbitrary File Deletion via Path TraversalEPSS 0.2%CVE-2023-26282MEDIUMIBM Watson CP4D Data Stores file modificiationEPSS 0.2%CVE-2025-1056MEDIUMGee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A nEPSS 0.2%CVE-2026-73770HIGHAuthenticated Arbitrary File Write Vulnerability Leading to Remote Code Execution in AOS-CXEPSS 0.2%CVE-2026-50158HIGHyutu: Arbitrary File Write via MCP `caption-download` ToolEPSS 0.2%CVE-2026-10558MEDIUMSourceCodester Pizzafy Ecommerce System index.php file inclusionEPSS 0.2%CVE-2026-10559MEDIUMSourceCodester Pizzafy Ecommerce System index.php file inclusionEPSS 0.2%CVE-2026-27115HIGHADB Explorer is Vulnerable to Arbitrary Directory Deletion via Command-Line ArgumentEPSS 0.2%CVE-2026-19860MEDIUMJetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation CallbackEPSS 0.2%