Fallos del tipo CWE-862

8589 resultados

Falta de verificação de autorização

O software permite que um usuário acesse recursos ou execute ações sem verificar se ele tem permissão para isso. O código autentica (confirma quem é), mas não autoriza (verifica o que pode fazer). Resultado: qualquer autenticado pode fazer o que quiser — ler dados de outros usuários, deletar registros, alterar configurações.

Ejemplo

Uma API de banco de dados que autentica o cliente via token JWT, mas retorna qualquer registro solicitado sem checar se o usuário é dono do dado. Um usuário autenticado consegue consultar CPF, conta bancária e extrato de qualquer outro cliente apenas mudando um parâmetro ID na requisição.

Cómo mitigar

Implemente controle de acesso em cada operação sensível: antes de retornar um recurso, valide se o usuário autenticado tem permissão (via papel, proprietário, ou ACL). Use um padrão consistente — biblioteca de autorização, middleware ou serviço centralizado — para não deixar brechas espalhadas no código.

CVE-2024-33635HIGHWordPress Piotnet Addons For Elementor Pro plugin <= 7.1.17 - Unauthenticated Arbitrary Post/Page Deletion vulnerabilityEPSS 0.6%CVE-2026-6804MEDIUMAI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX ActionsEPSS 0.6%CVE-2026-11398MEDIUMLatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer StepEPSS 0.6%CVE-2026-12406MEDIUMUser Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' ParameterEPSS 0.6%CVE-2026-11995MEDIUMGutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action()EPSS 0.6%CVE-2026-30797CRITICALRustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled ServerEPSS 0.6%CVE-2023-44227HIGHWordPress Simple File List Plugin <= 6.1.9 is vulnerable to Arbitrary File DeletionEPSS 0.6%CVE-2026-22172CRITICALOpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth ConnectionsEPSS 0.6%CVE-2023-6158MEDIUMEventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_metaEPSS 0.6%CVE-2023-2715MEDIUMGroundhogg <= 2.7.9.8 - Missing Authorization to Admin Account and Ticket CreationEPSS 0.6%CVE-2022-39975MEDIUMThe Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check EPSS 0.6%CVE-2026-75027MEDIUMThemify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via 'tb_update_old_data' AJAX ActionEPSS 0.6%CVE-2024-1807MEDIUMProduct Sort and Display for WooCommerce <= 2.4.1 - Missing AuthorizationEPSS 0.6%CVE-2024-33597HIGHWordPress SSU plugin <= 1.5.0 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2023-41848MEDIUMWordPress Carousel Slider plugin <= 2.2.2 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2026-86777MEDIUMAlchemyCMS before 7.4.16 and 8.x before 8.3.6 Missing Authorization on GET /api/nodesEPSS 0.6%CVE-2024-33667MEDIUMAn issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoinEPSS 0.6%CVE-2026-64746CRITICALAn authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26EPSS 0.6%CVE-2024-3936MEDIUMThe Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing AuthorizationEPSS 0.6%CVE-2024-3206MEDIUMDifferent Menu in Different Pages – Control Menu Visibility (All in One) <= 2.3.2 - Missing Authorization to Menu DuplicationEPSS 0.6%