Fallos del tipo CWE-862

8876 resultados

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para isso. O código autentica (confirma quem é), mas não autoriza (verifica o que pode fazer). Resultado: qualquer autenticado pode fazer o que quiser — ler dados de outros usuários, deletar registros, alterar configurações.

Ejemplo

Uma API de banco de dados que autentica o cliente via token JWT, mas retorna qualquer registro solicitado sem checar se o usuário é dono do dado. Um usuário autenticado consegue consultar CPF, conta bancária e extrato de qualquer outro cliente apenas mudando um parâmetro ID na requisição.

Cómo mitigar

Implemente controle de acesso em cada operação sensível: antes de retornar um recurso, valide se o usuário autenticado tem permissão (via papel, proprietário, ou ACL). Use um padrão consistente — biblioteca de autorização, middleware ou serviço centralizado — para não deixar brechas espalhadas no código.

CVE-2025-62884MEDIUMWordPress Coupon Affiliates plugin <= 7.2.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-92713HIGHModula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' ParameterEPSS 0.3%CVE-2025-14029MEDIUMCommunity Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' ParameterEPSS 0.3%CVE-2025-62892MEDIUMWordPress Sunshine Photo Cart plugin <= 3.5.3 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-8547HIGHInsufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromisEPSS 0.3%CVE-2026-105680MEDIUMGhost: Authorization Issue Allowed Author Role to Delete any PostEPSS 0.3%CVE-2025-60121MEDIUMWordPress WooEvents plugin <= 4.1.7 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-87605MEDIUMMissing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer processEPSS 0.3%CVE-2026-79184MEDIUMMissing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process EPSS 0.3%CVE-2026-87622MEDIUMMissing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HEPSS 0.3%CVE-2026-81916MEDIUMIncorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized ObjectEPSS 0.3%CVE-2026-18120MEDIUMMissing Authorization in legacy Express entries search endpoint allows disclosure of Express entry dataEPSS 0.3%CVE-2026-18421LOWConcrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authorization check, allowing a low-privileged board editor to modify or delete configured data sources on boards they do not controlEPSS 0.3%CVE-2026-79104MEDIUMMissing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process tEPSS 0.3%CVE-2025-59021MEDIUMTYPO3 CMS Allows Broken Access Control in Redirects ModuleEPSS 0.3%CVE-2026-0817MEDIUMCampaignEvents API missing authorization exposes meeting and chat URLsEPSS 0.3%CVE-2026-79085MEDIUMMissing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process EPSS 0.3%CVE-2025-14339MEDIUMweMail <= 2.0.7 - Missing Authorization to Unauthenticated Form DeletionEPSS 0.3%CVE-2024-13243MEDIUMEntity Delete Log - Moderately critical - Access bypass - SA-CONTRIB-2024-007EPSS 0.3%CVE-2025-3780MEDIUMWCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings ModificationEPSS 0.3%