Fallos del tipo CWE-863

3088 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-78606MEDIUMIncorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of DataEPSS 0.2%CVE-2025-24920MEDIUMUnauthorized Bookmark Creation and Modification in Archived ChannelsEPSS 0.2%CVE-2023-27899HIGHJenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions EPSS 0.2%CVE-2025-41078HIGHMultiple vulnerabilities in Viafirma productsEPSS 0.2%CVE-2026-100540HIGHOpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled AccountEPSS 0.2%CVE-2026-59815MEDIUMJoplin: Pending share recipients can write items into shared folders before accepting invitationsEPSS 0.2%CVE-2025-68153HIGHJuju: Resource poisoningEPSS 0.2%CVE-2025-30750LOWVulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 andEPSS 0.2%CVE-2022-31644HIGHPotential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escEPSS 0.2%CVE-2022-31646HIGHPotential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escEPSS 0.2%CVE-2026-79002LOWIncorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2021-4275MEDIUMkatlings pyambic-pentameter cross-site request forgeryEPSS 0.2%CVE-2026-53860LOWOpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubblesEPSS 0.2%CVE-2026-84743LOWThe Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer Update, Trash and Ownership Takeover via by-slug REST RoutesEPSS 0.2%CVE-2026-79186LOWIncorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer procesEPSS 0.2%CVE-2026-89151LOWForgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.EPSS 0.2%CVE-2026-79191LOWIncorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2023-6400HIGHIncorrect user authorization vulnerability on OpenText ZENworks Configuration Management (ZCM) product.EPSS 0.2%CVE-2025-10908HIGHAccount Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized AccessEPSS 0.2%CVE-2026-16064MEDIUMEvent Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_eventEPSS 0.2%