Fallos del tipo CWE-862

8836 resultados

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para isso. O código autentica (confirma quem é), mas não autoriza (verifica o que pode fazer). Resultado: qualquer autenticado pode fazer o que quiser — ler dados de outros usuários, deletar registros, alterar configurações.

Ejemplo

Uma API de banco de dados que autentica o cliente via token JWT, mas retorna qualquer registro solicitado sem checar se o usuário é dono do dado. Um usuário autenticado consegue consultar CPF, conta bancária e extrato de qualquer outro cliente apenas mudando um parâmetro ID na requisição.

Cómo mitigar

Implemente controle de acesso em cada operação sensível: antes de retornar um recurso, valide se o usuário autenticado tem permissão (via papel, proprietário, ou ACL). Use um padrão consistente — biblioteca de autorização, middleware ou serviço centralizado — para não deixar brechas espalhadas no código.

CVE-2026-22492MEDIUMWordPress Docket Cache plugin <= 24.07.04 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-78204MEDIUMGhostwriter through 7.2.6 Missing Authorization on Report Template Lint EndpointsEPSS 0.3%CVE-2026-82267MEDIUMKomodo Resource Identifier Disclosure and Audit Log Pollution Before Permission CheckEPSS 0.3%CVE-2026-18779MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_bookedEPSS 0.3%CVE-2026-44794MEDIUMNautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to referenceEPSS 0.3%CVE-2026-18777MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_statusEPSS 0.3%CVE-2025-12826MEDIUMCustom Post Type UI <= 1.18.0 - Missing Authorization to Unauthenticated (Previously Administrator+) Custom Post Type ModificationEPSS 0.3%CVE-2025-7956MEDIUMAjax Search Lite <= 4.13.1 - Missing Authorization to Unauthenticated Basic Information Exposure via ASL_Query in AJAX Search HandlerEPSS 0.3%CVE-2026-75798MEDIUMAI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor AssistantEPSS 0.3%CVE-2026-95297MEDIUMMissing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via EPSS 0.3%CVE-2026-67233MEDIUMRabbitMQ: Monitoring-tag user can DELETE shovelsEPSS 0.3%CVE-2024-13737MEDIUMMotors – Car Dealer, Classifieds & Listing <= 1.4.57 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Listing Template CreationEPSS 0.3%CVE-2026-100617HIGHCap-go capgo.app Authorization Bypass via channel_permission_overridesEPSS 0.3%CVE-2026-18965HIGHMissing Authorization in PayRange APIEPSS 0.3%CVE-2025-5900MEDIUMTenda AC9 cross-site request forgeryEPSS 0.3%CVE-2025-13318MEDIUMBooking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' ParameterEPSS 0.3%CVE-2026-53626HIGHGLPI: Arbitrary Document Read via Form Context Authorization BypassEPSS 0.3%CVE-2025-59017MEDIUMBroken Access Control in Backend AJAX RoutesEPSS 0.3%CVE-2026-0814MEDIUMAdvanced CF7 DB <= 2.0.9 - Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel ExportEPSS 0.3%CVE-2024-13312MEDIUMOpen Social - Moderately critical - Access bypass - SA-CONTRIB-2024-076EPSS 0.3%