Fallos del tipo CWE-807

109 resultados

Decisão de segurança baseada em entrada não confiável

A aplicação toma decisões críticas de segurança (autenticação, autorização, validação) usando dados que vêm do usuário ou de fontes externas sem validação adequada. Um atacante manipula essas entradas para contornar controles de segurança, como falsificar permissões ou contornar autenticação.

Ejemplo

Um sistema de login que verifica se o usuário é administrador consultando um parâmetro GET enviado pelo cliente (ex: ?admin=true) em vez de validar contra a sessão no servidor. O atacante muda o parâmetro e ganha acesso administrativo.

Cómo mitigar

Sempre valide e confie apenas em dados armazenados no servidor (sessão, banco de dados, tokens assinados). Nunca use parâmetros do cliente para decisões de segurança sem verificação de integridade — se for usar entrada externa, valide contra uma fonte confiável de autoridade.

CVE-2026-27707HIGHPlex-configured Seerr instances vulnerable to unauthenticated account registration via Jellyfin authentication endpointEPSS 0.5%CVE-2024-7005HIGHInsufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced EPSS 0.5%CVE-2026-31892HIGHWorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference ModeEPSS 0.5%CVE-2025-59152HIGHX-Forwarded-For Header Spoofing Bypasses Litestar Rate LimitingEPSS 0.5%CVE-2026-64827CRITICALTelenia TVox 26.5.3 Authentication Bypass via set_env.phpEPSS 0.5%CVE-2024-52327MEDIUMECOVACS lawnmower and vacuum cloud service live video PIN bypassEPSS 0.5%CVE-2025-66507HIGH1Panel – CAPTCHA Bypass via Client-Controlled FlagEPSS 0.5%CVE-2024-21510MEDIUMVersions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XEPSS 0.5%CVE-2026-59157MEDIUMwebhookd: Unrestricted HTTP Header to Shell Variable InjectionEPSS 0.5%CVE-2026-39807MEDIUMClient-supplied URI scheme trusted without transport verification in banditEPSS 0.5%CVE-2025-13926CRITICALContemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security DecisionEPSS 0.4%CVE-2025-24369LOWAnubis has a bot protection bypass when a sophisticated attacker asks to pass a challenge of difficulty 0EPSS 0.4%CVE-2026-16093MEDIUMKeycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headersEPSS 0.4%CVE-2026-13059HIGHImproper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control BypassEPSS 0.4%CVE-2026-54730HIGHauthentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageViewEPSS 0.4%CVE-2020-5252MEDIUMMalicious package may avoid detection in python auditingEPSS 0.4%CVE-2026-23848MEDIUMMyTube has Rate Limiting Bypass via X-Forwarded-For Header SpoofingEPSS 0.4%CVE-2026-25958HIGHCube privilege escalation via a specially crafted requestEPSS 0.4%CVE-2026-86863CRITICALpgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication modeEPSS 0.4%CVE-2024-45654MEDIUMIBM Security ReaQta improper input validationEPSS 0.4%