Fallos del tipo CWE-863

3097 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2024-40771HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS EPSS 0.2%CVE-2026-15829HIGHSQL Injection and Security Boundary Bypass in googleapis/mcp-toolboxEPSS 0.2%CVE-2025-64641MEDIUMMattermost Jira plugin crafted action leaks Jira issue detailsEPSS 0.2%CVE-2024-41979HIGHA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.2%CVE-2026-2386MEDIUMThe Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'EPSS 0.2%CVE-2025-24479HIGHFactoryTalk® View Machine Edition - Local Code InjectionEPSS 0.2%CVE-2026-35491MEDIUMPi-hole FTL: CLI API sessions can import Teleporter archives and modify configurationEPSS 0.2%CVE-2025-6707MEDIUMRace condition in privilege cache invalidation cycleEPSS 0.2%CVE-2024-12247MEDIUMImproper propagation of permission scheme updates across cluster nodesEPSS 0.2%CVE-2023-46139MEDIUMKernelSU signature validation mismatchEPSS 0.2%CVE-2024-47560HIGHRevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended EPSS 0.2%CVE-2026-18712HIGHImproper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other CollectionsEPSS 0.2%CVE-2023-29818MEDIUMAn issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections viEPSS 0.2%CVE-2026-46730MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.2%CVE-2025-43397MEDIUMA permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS TEPSS 0.2%CVE-2025-53391CRITICALThe Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactivEPSS 0.2%CVE-2025-66623HIGHStrimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operandsEPSS 0.2%CVE-2026-82748LOWAsh.Actions.Aggregate authorizes an aggregate under one action but computes it under anotherEPSS 0.2%CVE-2026-82749MEDIUMAsh relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped recordsEPSS 0.2%CVE-2026-58494MEDIUMWasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destinationEPSS 0.2%