Fallos del tipo CWE-863

3088 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-16064MEDIUMEvent Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_eventEPSS 0.2%CVE-2026-39350MEDIUMIstio AuthorizationPolicy Incorrect Regex Matching of Dots in serviceAccounts Fields Allows Policy BypassEPSS 0.2%CVE-2026-77425MEDIUMUnleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit logEPSS 0.2%CVE-2025-10908HIGHAccount Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized AccessEPSS 0.2%CVE-2025-43459MEDIUMAn authentication issue was addressed with improved state management. This issue is fixed in watchOS 26.1. An attacker with physical access EPSS 0.2%CVE-2023-6400HIGHIncorrect user authorization vulnerability on OpenText ZENworks Configuration Management (ZCM) product.EPSS 0.2%CVE-2022-34397MEDIUM Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypassEPSS 0.2%CVE-2026-84742LOWThe Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via TEC V1 REST APIEPSS 0.2%CVE-2025-42939MEDIUMMissing Authorization Check in SAP S/4HANA (Manage Processing Rules - For Bank Statements)EPSS 0.2%CVE-2026-23964MEDIUMMastodon has insufficient access control to push notification settingsEPSS 0.2%CVE-2026-100392HIGHInvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (Missing Object-Level Authorization)EPSS 0.2%CVE-2024-54010LOWUnauthenticated Traffic Handling Flaw Allows Packet Leakage on HPE Aruba Networking CX 10000 series switchesEPSS 0.2%CVE-2026-57590HIGHApache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project OperationsEPSS 0.2%CVE-2026-2465HIGHImproper Authorization in E-Kalite's Turboard FOR-SEPSS 0.2%CVE-2025-62394MEDIUMMoodle: quiz notifications sent to suspended participantsEPSS 0.2%CVE-2026-87540MEDIUMIncorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTMEPSS 0.2%CVE-2025-24500HIGHThe vulnerability allows an unauthenticated attacker to access information in PAM database.EPSS 0.2%CVE-2026-48772CRITICALProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACLEPSS 0.2%CVE-2026-1768MEDIUMA permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issEPSS 0.2%CVE-2026-80341MEDIUMPayment Plugins for PayPal WooCommerce < 2.0.26 - Subscriber+ Stored Payment Method Assignment via IDOREPSS 0.2%