Fallos del tipo CWE-863

3099 resultados

Falha na verificação de autorização

O software implementa uma verificação de acesso, mas a lógica está incorreta ou incompleta, permitindo que um usuário acesse recursos ou execute ações que não deveria. O risco é grave porque a autenticação (você é quem diz ser) pode estar correta, mas a autorização (você tem direito a isto?) falha, abrindo brechas para escalação de privilégios ou acesso a dados sensíveis.

Ejemplo

Uma API verifica se o usuário está logado antes de retornar dados de perfil, mas não valida se ele é dono do perfil consultado. Um atacante consegue acessar dados de outros usuários apenas mudando um ID na requisição. Ou um sistema de permissões usa condições OR quando deveria usar AND, liberando acesso para mais atores que o pretendido.

Cómo mitigar

Implemente controle de acesso a cada operação sensível verificando explicitamente se o usuário autenticado tem permissão específica para aquele recurso (não assuma contexto). Use bibliotecas de autorização consolidadas, testes unitários que validem negação de acesso, e revise a lógica de permissões regularmente, especialmente em APIs e operações administrativas.

CVE-2026-82747MEDIUMAsh.Policy.Authorizer returns records denied by a runtime read policy to any actorEPSS 0.2%CVE-2026-82748LOWAsh.Actions.Aggregate authorizes an aggregate under one action but computes it under anotherEPSS 0.2%CVE-2026-58494MEDIUMWasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destinationEPSS 0.2%CVE-2026-82749MEDIUMAsh relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped recordsEPSS 0.2%CVE-2026-77234CRITICALImproper input validation in FreeRTOS-Kernel timer command handlingEPSS 0.2%CVE-2025-41436LOWUnauthorized access to archived channel content via threads interfaceEPSS 0.2%CVE-2025-26850CRITICALThe agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation EPSS 0.2%CVE-2026-7867HIGHUdisks2: udisks2: local privilege escalation via as-user option spoofingEPSS 0.2%CVE-2024-21120MEDIUMVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions thatEPSS 0.2%CVE-2025-10015MEDIUMTCC Bypass via Downloader XPC Service in SparkleEPSS 0.2%CVE-2026-26963MEDIUMCilium may not enforce host firewall policies when Native Routing, WireGuard and Node Encryption are enabledEPSS 0.2%CVE-2025-8148MEDIUMCVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFTEPSS 0.2%CVE-2023-3485LOWInsecure Default Authorization in Temporal ServerEPSS 0.2%CVE-2026-56074MEDIUMPraisonAI - Tool Approval Cache Bypass via Coarse-Grained CachingEPSS 0.2%CVE-2026-92529MEDIUMIncorrect Authorization in GitLabEPSS 0.2%CVE-2025-64707LOWFrappe LMS revoking access did not show immediate effect as roles were cachedEPSS 0.2%CVE-2026-24692MEDIUMGuest users can bypass read permissions via search APIEPSS 0.2%CVE-2023-7047— Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop ManagerEPSS 0.2%CVE-2024-42013MEDIUMIn GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attacker with Windows admEPSS 0.2%CVE-2025-43251MEDIUMAn authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.6. A local attacker may gain acEPSS 0.2%