Fallos del tipo CWE-807

87 resultados

Decisão de segurança baseada em entrada não confiável

A aplicação toma decisões críticas de segurança (autenticação, autorização, validação) usando dados que vêm do usuário ou de fontes externas sem validação adequada. Um atacante manipula essas entradas para contornar controles de segurança, como falsificar permissões ou contornar autenticação.

Ejemplo

Um sistema de login que verifica se o usuário é administrador consultando um parâmetro GET enviado pelo cliente (ex: ?admin=true) em vez de validar contra a sessão no servidor. O atacante muda o parâmetro e ganha acesso administrativo.

Cómo mitigar

Sempre valide e confie apenas em dados armazenados no servidor (sessão, banco de dados, tokens assinados). Nunca use parâmetros do cliente para decisões de segurança sem verificação de integridade — se for usar entrada externa, valide contra uma fonte confiável de autoridade.

CVE-2026-34486CRITICALApache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptorEPSS 81.2%KEVCVE-2026-21509HIGHMicrosoft Office Security Feature Bypass VulnerabilityEPSS 72.2%KEVCVE-2024-13974HIGHA business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controEPSS 6.7%CVE-2021-41129HIGHAuthentication bypass in PterodactylEPSS 1.8%CVE-2026-21514HIGHMicrosoft Word Security Feature Bypass VulnerabilityEPSS 1.5%KEVCVE-2025-49827CRITICALConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM AuthenticatorEPSS 1.4%CVE-2021-31999HIGHRancher: Privilege escalation vulnerability via malicious Connection headerEPSS 1.1%CVE-2024-29039CRITICALMissing check in tpm2_checkquote allows attackers to misrepresent the TPM stateEPSS 1.0%CVE-2026-20849HIGHWindows Kerberos Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2021-36777HIGHlogin-proxy sends password to attacker-provided domainEPSS 0.9%CVE-2022-20744MEDIUMCisco Firepower Management Center Software Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-24120CRITICALvm2: Sandbox Breakout Through Promise SpeciesEPSS 0.9%CVE-2017-0887Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by tEPSS 0.9%CVE-2021-29479HIGHCached redirect poisoning via X-Forwarded-Host headerEPSS 0.9%CVE-2025-12487CRITICALoobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution VulnerabilityEPSS 0.8%CVE-2025-12488CRITICALoobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution VulnerabilityEPSS 0.8%CVE-2023-46686MEDIUM A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre DiaEPSS 0.5%CVE-2024-51561CRITICALAuthentication bypass Vulnerability in AeroEPSS 0.5%CVE-2026-27707HIGHPlex-configured Seerr instances vulnerable to unauthenticated account registration via Jellyfin authentication endpointEPSS 0.5%CVE-2024-21510MEDIUMVersions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XEPSS 0.5%