Fallos del tipo CWE-863

3059 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2025-65900MEDIUMKalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient perEPSS 0.3%CVE-2025-36578MEDIUMDell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remoEPSS 0.3%CVE-2026-15229MEDIUMPinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price ManipulationEPSS 0.3%CVE-2026-44557MEDIUMOpen WebUI: Global Knowledge Base Enumeration via knowledge-bases Meta-CollectionEPSS 0.3%CVE-2026-79005MEDIUMIncorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderEPSS 0.3%CVE-2026-61788HIGH@bytebase/dbhub's read-only mode does not prevent database writesEPSS 0.3%CVE-2025-24400MEDIUMJenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, aEPSS 0.3%CVE-2026-44850HIGHPortainer: Bind-mount restriction bypass via HostConfig.MountsEPSS 0.3%CVE-2026-54244LOWStatamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editorsEPSS 0.3%CVE-2024-13290MEDIUMOhDear Integration - Moderately critical - Access bypass - SA-CONTRIB-2024-056EPSS 0.3%CVE-2025-13829HIGHIncorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any EPSS 0.3%CVE-2026-79060MEDIUMIncorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderEPSS 0.3%CVE-2024-13302MEDIUMPages Restriction Access - Critical - Access bypass - SA-CONTRIB-2024-068EPSS 0.3%CVE-2024-47780LOWInformation Disclosure in TYPO3 Page TreeEPSS 0.3%CVE-2026-11540MEDIUMIBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilitiesEPSS 0.3%CVE-2025-36120HIGHIBM Storage Virtualize privilege escalationEPSS 0.3%CVE-2026-79178MEDIUMIncorrect authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker tEPSS 0.3%CVE-2023-29766HIGHAn issue found in CrossX v.1.15.3 for Android allows a local attacker to cause an escalation of Privileges via the database files.EPSS 0.3%CVE-2025-69417MEDIUMIn the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrEPSS 0.3%CVE-2025-69416MEDIUMIn the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrEPSS 0.3%