Fallos del tipo CWE-863

3087 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-79199MEDIUMIncorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions viEPSS 0.2%CVE-2026-47081LOWAn issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. EPSS 0.2%CVE-2026-79143MEDIUMIncorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypEPSS 0.2%CVE-2026-79217MEDIUMIncorrect authorization in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restriEPSS 0.2%CVE-2026-47910MEDIUMDreamweaver Desktop | Incorrect Authorization (CWE-863)EPSS 0.2%CVE-2025-12555MEDIUMIncorrect Authorization in GitLabEPSS 0.2%CVE-2026-79003MEDIUMIncorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass EPSS 0.2%CVE-2024-4811LOWIn affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacEPSS 0.2%CVE-2025-62243MEDIUMInsecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 tEPSS 0.2%CVE-2026-79211MEDIUMIncorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass sysEPSS 0.2%CVE-2026-79050MEDIUMIncorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions viEPSS 0.2%CVE-2025-68660MEDIUMDiscourse AI Discover's continue conversation allows threat actor to impersonate userEPSS 0.2%CVE-2026-79228LOWIncorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2026-62221LOWOpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFromEPSS 0.2%CVE-2025-32093MEDIUMSyatem admin profile modification by delegated granular administration roleEPSS 0.2%CVE-2026-80204CRITICALGrav before 1.0.18 Authentication Bypass via Scoped API KeyEPSS 0.2%CVE-2021-3457—An improper authorization handling flaw was found in Foreman. The Shellhooks plugin for the smart-proxy allows Foreman clients to execute acEPSS 0.2%CVE-2020-35501—A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the EPSS 0.2%CVE-2024-2321MEDIUMIncorrect Authorization in Multiple WSO2 Products Allows API Access via Refresh TokenEPSS 0.2%CVE-2026-46549LOWNocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope EscalationEPSS 0.2%