Fallos del tipo CWE-863

3061 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-32991HIGHImproper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.EPSS 0.3%CVE-2026-48396HIGHBridge | Incorrect Authorization (CWE-863)EPSS 0.3%CVE-2026-100556MEDIUMOpenClaw before 2026.8.1 Authentication Bypass via Session ResetEPSS 0.3%CVE-2026-49092MEDIUMUnintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information ExposureEPSS 0.3%CVE-2025-22449LOWAccess control flaw for team admins allows unauthorized team additionsEPSS 0.3%CVE-2026-24487MEDIUMOpenEMR has FHIR Patient Compartment Bypass in CareTeam ResourceEPSS 0.3%CVE-2026-13061MEDIUMImproper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation StageEPSS 0.3%CVE-2026-90942CRITICALCasdoor through 4.4.0 Private Key Exposure via Certificate EndpointsEPSS 0.3%CVE-2024-20510MEDIUMA vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticEPSS 0.3%CVE-2026-56776MEDIUMn8n - Incorrect OAuth Scope Validation in Workflow Test Run EndpointEPSS 0.3%CVE-2026-100629HIGHCapgo backend before 12.127.5 Privilege Escalation via role_bindings PATCHEPSS 0.3%CVE-2026-54698MEDIUMHasura: Row-level authorization bypass on table computed fieldsEPSS 0.3%CVE-2026-88974MEDIUMWPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePostEPSS 0.3%CVE-2026-90923MEDIUMAutopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and DeletionEPSS 0.3%CVE-2025-2045MEDIUMIncorrect Authorization in GitLabEPSS 0.3%CVE-2026-41174MEDIUMTraefik Kubernetes CRD allows unauthorized cross-namespace middleware bindingEPSS 0.3%CVE-2026-53512CRITICALBetter Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsEPSS 0.3%CVE-2026-56723HIGHZammad: Missing authorization on ticket attachment downloadEPSS 0.3%CVE-2026-25127HIGHOpenEMR has Broken Access Control on Care Coordination ModuleEPSS 0.3%CVE-2026-44283NONEetcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checksEPSS 0.3%