Fallos del tipo CWE-863

2985 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2024-25170CRITICALAn issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.EPSS 0.9%CVE-2020-3467HIGHCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.9%CVE-2023-22482CRITICALJWT audience claim is not verifiedEPSS 0.9%CVE-2022-27642MEDIUMThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91EPSS 0.9%CVE-2026-85978CRITICALUnauthenticated Remote Code Execution in Akana API PlatformEPSS 0.9%CVE-2026-26265HIGHDiscourse has IDOR vulnerability in the directory items endpointEPSS 0.9%CVE-2022-29619Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit oEPSS 0.9%CVE-2023-40309CRITICALMissing Authorization check in SAP CommonCryptoLibEPSS 0.9%CVE-2026-47996MEDIUMAdobe Commerce | Incorrect Authorization (CWE-863)EPSS 0.9%CVE-2021-23203HIGHImproper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote attackEPSS 0.9%CVE-2024-26016MEDIUMApache Superset: Improper authorization validation on dashboards and charts importEPSS 0.9%CVE-2024-39352MEDIUMA vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users witEPSS 0.9%CVE-2025-21519MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected aEPSS 0.9%CVE-2020-25240A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guesEPSS 0.9%CVE-2021-41230MEDIUMOIDC claims not updated from Identity Provider in PomeriumEPSS 0.9%CVE-2022-42978HIGHIn the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could accessEPSS 0.9%CVE-2021-24742Logo Slider and Showcase < 1.3.37 - Editor Plugin's Settings UpdateEPSS 0.9%CVE-2023-27486HIGHInsufficient authorization validation between zones when xCAT zones are enabledEPSS 0.9%CVE-2021-24770Stylish Price List < 6.9.1 - Subscriber+ Arbitrary Image UploadEPSS 0.9%CVE-2023-22500HIGHglpi Unauthorized access to inventory filesEPSS 0.9%