Fallos del tipo CWE-73

671 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2026-5054HIGHNoMachine External Control of File Path Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-55609HIGHsublinear-time-solver: Arbitrary file write in consciousness-explorer / sublinear-time-solver MCP export_stateEPSS 0.2%CVE-2026-26158HIGHBusybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entriesEPSS 0.2%CVE-2024-33671HIGHAn issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can bEPSS 0.2%CVE-2026-80118HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTLEPSS 0.2%CVE-2024-23317MEDIUMExternal Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the ControEPSS 0.2%CVE-2026-52875HIGHStreambert: Arbitrary Directory Creation and File Manipulation via Backup HandlerEPSS 0.2%CVE-2026-30905HIGHExternal Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenEPSS 0.2%CVE-2026-25636HIGHcalibre has a Path Traversal Leading to Arbitrary File Corruption and Code ExecutionEPSS 0.2%CVE-2026-0965LOWLibssh: libssh: denial of service via improper configuration file handlingEPSS 0.2%CVE-2023-28603HIGHZoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete localEPSS 0.2%CVE-2026-8921HIGHExternal Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM priviEPSS 0.2%CVE-2026-16898HIGHIBM i is Affected By Multiple Vulnerabilities in Network Authentication ServiceEPSS 0.2%CVE-2026-16987HIGHIBM i is Affected By An Improper Validation Vulnerability in PASE []EPSS 0.2%CVE-2025-64738MEDIUMZoom Workplace for macOS - External Control of File Name or PathEPSS 0.2%CVE-2026-93987MEDIUMrclone serve docker Path Traversal via Volume NameEPSS 0.2%CVE-2026-81830MEDIUMThe Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directoEPSS 0.2%CVE-2026-49358LOWPhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFilesEPSS 0.1%CVE-2026-18806HIGHArbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardus-image-writerEPSS 0.1%CVE-2026-5053HIGHNoMachine External Control of File Path Arbitrary File Deletion VulnerabilityEPSS 0.1%