Fallos del tipo CWE-862

8756 resultados

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para isso. O código autentica (confirma quem é), mas não autoriza (verifica o que pode fazer). Resultado: qualquer autenticado pode fazer o que quiser — ler dados de outros usuários, deletar registros, alterar configurações.

Ejemplo

Uma API de banco de dados que autentica o cliente via token JWT, mas retorna qualquer registro solicitado sem checar se o usuário é dono do dado. Um usuário autenticado consegue consultar CPF, conta bancária e extrato de qualquer outro cliente apenas mudando um parâmetro ID na requisição.

Cómo mitigar

Implemente controle de acesso em cada operação sensível: antes de retornar um recurso, valide se o usuário autenticado tem permissão (via papel, proprietário, ou ACL). Use um padrão consistente — biblioteca de autorização, middleware ou serviço centralizado — para não deixar brechas espalhadas no código.

CVE-2026-87606HIGHMissing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer prEPSS 0.3%CVE-2024-5382MEDIUMMaster Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to MA Template Creation or ModificationEPSS 0.3%CVE-2023-1774MEDIUMUnauthorized email invite to a private channelEPSS 0.3%CVE-2026-2371MEDIUMGreenshift <= 12.8.3 - Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load'EPSS 0.3%CVE-2024-54218MEDIUMWordPress AIO Contact plugin <= 2.8.1 - Unauthenticated Plugin Settings Change vulnerabilityEPSS 0.3%CVE-2024-45307HIGHSudoBot missing authorization check in `-config` commandEPSS 0.3%CVE-2024-6755MEDIUMSocial Auto Poster <= 5.3.14 - Missing Authorization to Unauthenticated Arbitrary Post DeletionEPSS 0.3%CVE-2026-71308HIGHLemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificatesEPSS 0.3%CVE-2023-40209MEDIUMWordPress Highcompress Image Compressor plugin <= 6.0.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-9584MEDIUMImage Map Pro <= 6.0.20 - Missing Authorization to Authenticated (Contributor+) Map Project Add/Update/DeleteEPSS 0.3%CVE-2024-49694MEDIUMWordPress My Wp Brand – Hide menu & Hide Plugin plugin <= 1.1.2 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-94384MEDIUMMissing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce LambdaEPSS 0.3%CVE-2026-101139MEDIUMWebkul Bagisto Invoice Mass Status Update state authorizationEPSS 0.3%CVE-2026-23632MEDIUMGogs user can update repository content with read-only permissionEPSS 0.3%CVE-2023-46195MEDIUMWordPress Headline Analyzer plugin <= 1.3.1 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2023-7287MEDIUMPaytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'pt_cancel_subscription'EPSS 0.3%CVE-2024-11134MEDIUMEventer <= 3.9.9 - Missing Authorization to Authenticated (Subscriber+) Bookings ExportEPSS 0.3%CVE-2024-5857MEDIUMInteractive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media DeletionEPSS 0.3%CVE-2026-45703MEDIUMPimcore: WordExport Authorization Bypass for Unauthorized Document ExportEPSS 0.3%CVE-2025-7772MEDIUMMalcure Malware Scanner — #1 Toolset for WordPress Malware Removal <= 16.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.3%