Fallos del tipo CWE-807

109 resultados

Decisão de segurança baseada em entrada não confiável

A aplicação toma decisões críticas de segurança (autenticação, autorização, validação) usando dados que vêm do usuário ou de fontes externas sem validação adequada. Um atacante manipula essas entradas para contornar controles de segurança, como falsificar permissões ou contornar autenticação.

Ejemplo

Um sistema de login que verifica se o usuário é administrador consultando um parâmetro GET enviado pelo cliente (ex: ?admin=true) em vez de validar contra a sessão no servidor. O atacante muda o parâmetro e ganha acesso administrativo.

Cómo mitigar

Sempre valide e confie apenas em dados armazenados no servidor (sessão, banco de dados, tokens assinados). Nunca use parâmetros do cliente para decisões de segurança sem verificação de integridade — se for usar entrada externa, valide contra uma fonte confiável de autoridade.

CVE-2026-35617LOWOpenClaw < 2026.3.25 - Authorization Bypass via Group Policy Rebinding with Mutable Space displayNameEPSS 0.2%CVE-2026-35670MEDIUMOpenClaw < 2026.3.22 - Webhook Reply Rebinding via Username Resolution in Synology ChatEPSS 0.2%CVE-2024-9310MEDIUMTraffic Alert and Collision Avoidance System (TCAS) II has a Reliance on Untrusted Inputs in a Security Decision vulnerabilityEPSS 0.2%CVE-2026-35655MEDIUMOpenClaw < 2026.3.22 - Identity Spoofing via rawInput Tool in ACP Permission ResolutionEPSS 0.2%CVE-2026-29134MEDIUMGINA Domain SwitchEPSS 0.2%CVE-2026-58239LOWMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.2%CVE-2026-44649CRITICALSillyTavern: Authentication Bypass via SSO Header InjectionEPSS 0.2%CVE-2025-55735MEDIUMflaskBlog Stored XSS VulnerabilityEPSS 0.2%CVE-2026-64934MEDIUMMira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decisionEPSS 0.2%CVE-2019-25711MEDIUMSpotFTP Password Recover 2.4.2 Denial of Service via Name FieldEPSS 0.2%CVE-2026-41299HIGHOpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance GuardEPSS 0.2%CVE-2026-9561HIGHEclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP addrEPSS 0.2%CVE-2019-25544MEDIUMPidgin 2.13.0 Denial of Service via Malformed UsernameEPSS 0.2%CVE-2019-25621MEDIUMPixel Studio 2.17 Denial of Service via Malformed InputEPSS 0.2%CVE-2024-28824HIGHPrivilege escalation in mk_informix pluginEPSS 0.2%CVE-2023-0009HIGHGlobalProtect App: Local Privilege Escalation (PE) VulnerabilityEPSS 0.2%CVE-2024-28829MEDIUMPrivilege escalation in mk_informix pluginEPSS 0.2%CVE-2026-48980MEDIUMpam_usb: getenv() used in PAM context allows environment variable injection into local-check logicEPSS 0.2%CVE-2026-53860LOWOpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubblesEPSS 0.2%CVE-2026-12058MEDIUMThe connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.EPSS 0.2%