Fallos del tipo CWE-863

3086 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-73571LOWAn authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegaEPSS 0.3%CVE-2024-49209MEDIUMArcher Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application fiEPSS 0.3%CVE-2026-100538HIGHOpenClaw before 2026.8.1 Local File Read via Outbound AttachmentsEPSS 0.3%CVE-2026-59689HIGHProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to RootEPSS 0.3%CVE-2026-78946MEDIUMIncorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafteEPSS 0.3%CVE-2026-79077MEDIUMIncorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictionsEPSS 0.3%CVE-2024-57969MEDIUMapp/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.EPSS 0.3%CVE-2026-79213MEDIUMIncorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system aEPSS 0.3%CVE-2025-13480MEDIUMIncorrect authorization in Fudo EnterpriseEPSS 0.3%CVE-2026-79261MEDIUMIncorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafEPSS 0.3%CVE-2026-45316LOWOpen WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)EPSS 0.3%CVE-2026-28720MEDIUMUnauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 1EPSS 0.3%CVE-2025-43784MEDIUMImproper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 thrEPSS 0.3%CVE-2026-28709MEDIUMUnauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (LinuEPSS 0.3%CVE-2026-28719MEDIUMUnauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (LinuEPSS 0.3%CVE-2026-28723MEDIUMUnauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, WindoEPSS 0.3%CVE-2024-49208MEDIUMArcher Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supporting application files.EPSS 0.3%CVE-2024-44114LOWMissing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.3%CVE-2026-33343NONEetcd: Nested etcd transactions bypass RBAC authorization checksEPSS 0.3%CVE-2026-22170MEDIUMOpenClaw < 2026.2.22 BlueBubbles - Access Control Bypass via Empty allowFrom ConfigurationEPSS 0.3%