Fallos del tipo CWE-73

668 resultados

Controle de acesso inadequado

A aplicação falha em validar ou reforçar adequadamente quem pode acessar determinados recursos, funcionalidades ou dados. Um usuário consegue executar ações ou visualizar informações para as quais não deveria ter permissão, porque o sistema não verifica corretamente as credenciais ou privilégios.

Ejemplo

Uma API de e-commerce permite que qualquer usuário logado modifique pedidos alheios mudando apenas o ID na URL (ex: /pedido/123 para /pedido/124), sem verificar se o pedido pertence a quem faz a requisição. Outro caso: um painel administrativo é acessível apenas alterando uma flag no navegador ou sendo deixado públicamente sem autenticação.

Cómo mitigar

Implemente verificações de autorização em toda operação sensível (sempre validar que o usuário é dono ou tem permissão explícita). Use listas de controle de acesso (ACL) ou modelos RBAC/ABAC centralizados e não confie apenas em obfuscação de IDs ou dados do lado do cliente. Teste acesso com usuários de diferentes papéis para garantir isolamento.

CVE-2024-38049MEDIUMWindows Distributed Transaction Coordinator Remote Code Execution VulnerabilityEPSS 1.6%CVE-2020-15264HIGHPrivilege Escalation in BoxstarterEPSS 1.6%CVE-2024-11042CRITICALArbitrary File Delete in invoke-ai/invokeaiEPSS 1.5%CVE-2026-26975HIGHMusic Assistant Server Path Traversal in Playlist Update API Allows Remote Code ExecutionEPSS 1.5%CVE-2025-46762HIGHApache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadataEPSS 1.5%CVE-2020-26078MEDIUMCisco IoT Field Network Director File Overwrite VulnerabilityEPSS 1.5%CVE-2022-0593—Login with phone number < 1.3.7 - Unauthenticated remote plugin deletionEPSS 1.4%CVE-2020-5296MEDIUMArbitrary File Deletion vulnerability in OctoberCMSEPSS 1.4%CVE-2022-20789MEDIUMCisco Unified Communications Products Arbitrary File Write VulnerabilityEPSS 1.4%CVE-2019-3681HIGHosc: stores downloaded (supposed) RPM in network-controlled filesystem pathsEPSS 1.4%CVE-2025-4603CRITICALeMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File DeletionEPSS 1.4%CVE-2024-43581HIGHMicrosoft OpenSSH for Windows Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-27944HIGHA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmEPSS 1.4%CVE-2024-38029HIGHMicrosoft OpenSSH for Windows Remote Code Execution VulnerabilityEPSS 1.4%CVE-2026-8450CRITICALHTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()EPSS 1.4%CVE-2026-11526CRITICALGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandleEPSS 1.4%CVE-2024-27945HIGHA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a priEPSS 1.4%CVE-2025-49760LOWWindows Storage Spoofing VulnerabilityEPSS 1.3%CVE-2025-55746CRITICALDirectus allows unauthenticated file upload and file modification due to lacking input sanitizationEPSS 1.3%CVE-2024-38165MEDIUMWindows Compressed Folder Tampering VulnerabilityEPSS 1.3%