Fallos del tipo CWE-862

8626 resultados

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para isso. O código autentica (confirma quem é), mas não autoriza (verifica o que pode fazer). Resultado: qualquer autenticado pode fazer o que quiser — ler dados de outros usuários, deletar registros, alterar configurações.

Ejemplo

Uma API de banco de dados que autentica o cliente via token JWT, mas retorna qualquer registro solicitado sem checar se o usuário é dono do dado. Um usuário autenticado consegue consultar CPF, conta bancária e extrato de qualquer outro cliente apenas mudando um parâmetro ID na requisição.

Cómo mitigar

Implemente controle de acesso em cada operação sensível: antes de retornar um recurso, valide se o usuário autenticado tem permissão (via papel, proprietário, ou ACL). Use um padrão consistente — biblioteca de autorização, middleware ou serviço centralizado — para não deixar brechas espalhadas no código.

CVE-2025-23025CRITICALPrivilege escalation (PR) through realtime WYSIWYG editing in XWikiEPSS 0.4%CVE-2025-12714MEDIUMRank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings ModificationEPSS 0.4%CVE-2024-49325MEDIUMWordPress Photo Gallery Builder plugin <= 3.0 - Broken Access Control to Notice Dismissal vulnerabilityEPSS 0.4%CVE-2024-1798MEDIUMTutor LMS – Migration Tool <= 2.2.0 - Missing Authorization in tutor_lp_export_xmlEPSS 0.4%CVE-2024-9829MEDIUMDownload Plugin <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment DownloadEPSS 0.4%CVE-2025-26372HIGHA CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authEPSS 0.4%CVE-2025-2224MEDIUMDirectorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post PublishingEPSS 0.4%CVE-2025-54159HIGHMissing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrEPSS 0.4%CVE-2024-10078MEDIUMWP Easy Post Types <= 1.4.4 - Authenticated (Subscriber+) Missing Authorization via Multiple FunctionsEPSS 0.4%CVE-2024-9583MEDIUMRSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing AuthorizationEPSS 0.4%CVE-2026-67529MEDIUMOpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)EPSS 0.4%CVE-2024-1123MEDIUMEventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post OverwriteEPSS 0.4%CVE-2023-32129MEDIUMWordPress Editorialmag theme <= 1.1.9 - Authenticated Arbitrary Plugin ActivationEPSS 0.4%CVE-2026-3208MEDIUMMercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticated PIX Payment QR Code Image DisclosureEPSS 0.4%CVE-2026-57221MEDIUMRabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged usersEPSS 0.4%CVE-2024-55998MEDIUMWordPress Popup Surveys & Polls for WordPress (Mare.io) plugin <= 1.36 - Settings Change vulnerabilityEPSS 0.4%CVE-2023-4025MEDIUMRadio Player <= 2.0.73 - Missing Authorization to Player UpdateEPSS 0.4%CVE-2024-53806MEDIUMWordPress Maspik plugin <= 2.2.7 - CSRF to Settings Change vulnerabilityEPSS 0.4%CVE-2024-56004MEDIUMWordPress Easy Site Importer plugin <= 1.0.1 - Settings Change vulnerabilityEPSS 0.4%CVE-2025-24583MEDIUMWordPress 12 Step Meeting List plugin <= 3.16.5 - Settings Change vulnerabilityEPSS 0.4%